Vulnerabilities > Jaws Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-12-23 | CVE-2020-35657 | Unrestricted Upload of File with Dangerous Type vulnerability in Jaws Project Jaws 1.8.0 Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing a .php file that is able to execute OS commands. | 7.2 |
2020-12-23 | CVE-2020-35656 | Unrestricted Upload of File with Dangerous Type vulnerability in Jaws Project Jaws 1.8.0 Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadget&comp=FileBrowser and admin.php?reqGadget=FileBrowser&reqAction=Files to upload a .php file. | 7.2 |