Vulnerabilities > Jaws Project

DATE CVE VULNERABILITY TITLE RISK
2020-12-23 CVE-2020-35657 Unrestricted Upload of File with Dangerous Type vulnerability in Jaws Project Jaws
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing a .php file that is able to execute OS commands.
network
low complexity
jaws-project CWE-434
6.5
2020-12-23 CVE-2020-35656 Unrestricted Upload of File with Dangerous Type vulnerability in Jaws Project Jaws
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadget&comp=FileBrowser and admin.php?reqGadget=FileBrowser&reqAction=Files to upload a .php file.
network
low complexity
jaws-project CWE-434
6.5