Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2017-09-14 CVE-2017-1002000 Unrestricted Upload of File with Dangerous Type vulnerability in Mobile-Friendly-App-Builder-By-Easytouch Project Mobile-Friendly-App-Builder-By-Easytouch 3.0
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content.
9.8
2017-09-12 CVE-2017-14399 Unrestricted Upload of File with Dangerous Type vulnerability in Blackcat-Cms Blackcat CMS 1.2.2
In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing the extension from .jpg to .php.
network
low complexity
blackcat-cms CWE-434
8.8
2017-09-12 CVE-2017-14346 Unrestricted Upload of File with Dangerous Type vulnerability in Blog Project Blog
upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file.
network
low complexity
blog-project CWE-434
critical
9.8
2017-09-12 CVE-2015-9228 Unrestricted Upload of File with Dangerous Type vulnerability in Imagely Nextgen Gallery
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
network
low complexity
imagely CWE-434
8.8
2017-09-11 CVE-2017-14251 Unrestricted Upload of File with Dangerous Type vulnerability in Typo3
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.
network
low complexity
typo3 CWE-434
8.8
2017-09-04 CVE-2017-14123 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Firewall Analyzer 12.2
Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section.
network
low complexity
zohocorp CWE-434
8.8
2017-08-31 CVE-2017-14050 Unrestricted Upload of File with Dangerous Type vulnerability in Blackcat-Cms Blackcat CMS 1.2
In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .php file.
network
low complexity
blackcat-cms CWE-434
8.8
2017-08-29 CVE-2013-7426 Unrestricted Upload of File with Dangerous Type vulnerability in Kamailio 4.0.11
Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1.
network
low complexity
kamailio CWE-434
critical
9.8
2017-08-29 CVE-2016-0354 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Sametime
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges.
network
low complexity
ibm CWE-434
5.5
2017-08-28 CVE-2014-9312 Unrestricted Upload of File with Dangerous Type vulnerability in 10Web Photo Gallery 1.2.5
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
network
low complexity
10web CWE-434
8.8