Total
2367 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-14704 | 1 Claydip | 1 Airbnb Clone | 2017-10-10 | 6.5 MEDIUM | 8.8 HIGH |
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/profile. | |||||
CVE-2017-14958 | 1 Pivotx | 1 Pivotx | 2017-10-06 | 6.5 MEDIUM | 7.2 HIGH |
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file. | |||||
CVE-2015-8249 | 1 Manageengine | 1 Desktop Central | 2017-10-06 | 10.0 HIGH | 9.8 CRITICAL |
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter. | |||||
CVE-2017-14838 | 1 Teamworktec | 1 Job Links | 2017-10-06 | 6.5 MEDIUM | 8.8 HIGH |
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange. | |||||
CVE-2017-14839 | 1 Teamworktec | 1 Photo Fusion | 2017-10-06 | 6.5 MEDIUM | 8.8 HIGH |
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover. | |||||
CVE-2017-14840 | 1 Teamworktec | 1 Ticketplus | 2017-10-06 | 6.5 MEDIUM | 8.8 HIGH |
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile. | |||||
CVE-2017-14841 | 1 Dasinfomedia | 1 Annual Maintenance Contract Management System | 2017-10-05 | 4.0 MEDIUM | 6.5 MEDIUM |
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling. | |||||
CVE-2017-14079 | 1 Trendmicro | 1 Mobile Security | 2017-09-29 | 6.5 MEDIUM | 8.8 HIGH |
Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations. | |||||
CVE-2017-12929 | 1 Tecnovision | 1 Dlx Spot Player4 | 2017-09-29 | 6.5 MEDIUM | 8.8 HIGH |
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. | |||||
CVE-2017-1002003 | 1 Wp2android-turn-wp-site-into-android-app Project | 1 Wp2android-turn-wp-site-into-android-app | 2017-09-27 | 7.5 HIGH | 9.8 CRITICAL |
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com. | |||||
CVE-2017-1002002 | 1 Webapp-builder Project | 1 Webapp-builder | 2017-09-27 | 7.5 HIGH | 9.8 CRITICAL |
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/ | |||||
CVE-2017-1002001 | 1 Mobile-app-builder-by-wappress Project | 1 Mobile-app-builder-by-wappress | 2017-09-27 | 7.5 HIGH | 9.8 CRITICAL |
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com. | |||||
CVE-2017-1002000 | 1 Mobile-friendly-app-builder-by-easytouch Project | 1 Mobile-friendly-app-builder-by-easytouch | 2017-09-27 | 7.5 HIGH | 9.8 CRITICAL |
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content. | |||||
CVE-2014-9619 | 1 Netsweeper | 1 Netsweeper | 2017-09-27 | 6.5 MEDIUM | 7.2 HIGH |
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote authenticated users with admin privileges on the Cloud Manager web console to execute arbitrary PHP code by uploading a file with a double extension, then accessing it via a direct request to the file in webadmin/deny/images/, as demonstrated by secuid0.php.gif. | |||||
CVE-2017-14346 | 1 Blog Project | 1 Blog | 2017-09-26 | 7.5 HIGH | 9.8 CRITICAL |
upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file. | |||||
CVE-2017-14399 | 1 Blackcat-cms | 1 Blackcat Cms | 2017-09-19 | 6.5 MEDIUM | 8.8 HIGH |
In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing the extension from .jpg to .php. | |||||
CVE-2016-0354 | 1 Ibm | 1 Sametime | 2017-09-07 | 6.0 MEDIUM | 5.5 MEDIUM |
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893. | |||||
CVE-2013-7426 | 1 Kamailio | 1 Kamailio | 2017-09-02 | 7.5 HIGH | 9.8 CRITICAL |
Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1. | |||||
CVE-2017-14050 | 1 Blackcat-cms | 1 Blackcat Cms | 2017-09-01 | 6.5 MEDIUM | 8.8 HIGH |
In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .php file. | |||||
CVE-2017-3108 | 1 Adobe | 1 Experience Manager | 2017-08-16 | 7.5 HIGH | 9.8 CRITICAL |
Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability. |