Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
apache commons fileupload vulnerabilities and exploits
(subscribe to this query)
3.3
CVSSv2
CVE-2013-0248
The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack....
Apache Commons Fileupload 1.0
Apache Commons Fileupload 1.1
Apache Commons Fileupload 1.1.1
Apache Commons Fileupload 1.2
Apache Commons Fileupload 1.2.1
Apache Commons Fileupload 1.2.2
2 Github repositories available
NA
CVE-2023-24998
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new...
Apache Commons Fileupload
Apache Commons Fileupload 1.0
7.5
CVSSv2
CVE-2016-1000031
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution...
Apache Commons Fileupload
5 Github repositories available
3 Articles available
7.5
CVSSv2
CVE-2014-0050
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's...
Oracle Retail Applications 12.0
Oracle Retail Applications 12.0in
Oracle Retail Applications 13.2
Oracle Retail Applications 13.3
Oracle Retail Applications 13.4
Oracle Retail Applications 14.0
Oracle Retail Applications 13.0
Oracle Retail Applications 13.1
Apache Tomcat 7.0.0
Apache Tomcat 7.0.14
Apache Tomcat 7.0.15
Apache Tomcat 7.0.21
Apache Tomcat 7.0.22
Apache Tomcat 7.0.29
Apache Tomcat 7.0.3
Apache Tomcat 7.0.36
Apache Tomcat 7.0.37
Apache Tomcat 7.0.43
Apache Tomcat 7.0.44
Apache Tomcat 7.0.50
Apache Tomcat 7.0.6
Apache Tomcat 8.0.0
Apache Commons Fileupload 1.0
Apache Tomcat 7.0.10
Apache Tomcat 7.0.11
Apache Tomcat 7.0.19
Apache Tomcat 7.0.2
Apache Tomcat 7.0.25
Apache Tomcat 7.0.26
Apache Tomcat 7.0.32
Apache Tomcat 7.0.33
Apache Tomcat 7.0.4
Apache Tomcat 7.0.40
Apache Tomcat 7.0.47
Apache Tomcat 7.0.48
Apache Tomcat 7.0.9
Apache Commons Fileupload 1.2
Apache Commons Fileupload 1.2.1
Apache Tomcat 7.0.12
Apache Tomcat 7.0.13
Apache Tomcat 7.0.20
Apache Tomcat 7.0.27
Apache Tomcat 7.0.28
Apache Tomcat 7.0.34
Apache Tomcat 7.0.35
Apache Tomcat 7.0.41
Apache Tomcat 7.0.42
Apache Tomcat 7.0.49
Apache Tomcat 7.0.5
Apache Tomcat 8.0.1
Apache Commons Fileupload 1.2.2
Apache Commons Fileupload
Apache Tomcat 7.0.1
Apache Tomcat 7.0.16
Apache Tomcat 7.0.17
Apache Tomcat 7.0.18
Apache Tomcat 7.0.23
Apache Tomcat 7.0.24
Apache Tomcat 7.0.30
Apache Tomcat 7.0.31
Apache Tomcat 7.0.38
Apache Tomcat 7.0.39
Apache Tomcat 7.0.45
Apache Tomcat 7.0.46
Apache Tomcat 7.0.7
Apache Tomcat 7.0.8
Apache Commons Fileupload 1.1
Apache Commons Fileupload 1.1.1
1 EDB exploit available
1 Metasploit module available
10 Github repositories available
1 Article available
7.8
CVSSv2
CVE-2016-3092
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long...
Hp Icewall Sso Agent Option 10.0
Hp Icewall Identity Manager 5.0
Apache Tomcat 9.0.0
Apache Tomcat 8.0.32
Apache Tomcat 8.0.3
Apache Tomcat 8.0.30
Apache Tomcat 8.0.22
Apache Tomcat 8.0.21
Apache Tomcat 8.0.11
Apache Tomcat 8.0.1
Apache Tomcat 8.0.8
Apache Tomcat 8.0.5
Apache Tomcat 8.0.27
Apache Tomcat 8.0.26
Apache Tomcat 8.0.17
Apache Tomcat 8.0.15
Apache Tomcat 8.0.0
Apache Tomcat 8.0.35
Apache Tomcat 8.0.33
Apache Tomcat 8.0.24
Apache Tomcat 8.0.23
Apache Tomcat 8.0.14
Apache Tomcat 8.0.12
Apache Tomcat 8.0.29
Apache Tomcat 8.0.28
Apache Tomcat 8.0.20
Apache Tomcat 8.0.18
Debian Debian Linux 8.0
Apache Tomcat 8.5.2
Apache Tomcat 8.5.0
Apache Commons Fileupload
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 15.10
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 12.04
Apache Tomcat 7.0.65
Apache Tomcat 7.0.64
Apache Tomcat 7.0.55
Apache Tomcat 7.0.54
Apache Tomcat 7.0.53
Apache Tomcat 7.0.52
Apache Tomcat 7.0.61
Apache Tomcat 7.0.6
Apache Tomcat 7.0.59
Apache Tomcat 7.0.5
Apache Tomcat 7.0.47
Apache Tomcat 7.0.37
Apache Tomcat 7.0.35
Apache Tomcat 7.0.26
Apache Tomcat 7.0.25
Apache Tomcat 7.0.19
Apache Tomcat 7.0.16
Apache Tomcat 7.0.0
Apache Tomcat 7.0.8
Apache Tomcat 7.0.67
Apache Tomcat 7.0.57
Apache Tomcat 7.0.56
Apache Tomcat 7.0.42
Apache Tomcat 7.0.41
Apache Tomcat 7.0.34
Apache Tomcat 7.0.33
Apache Tomcat 7.0.23
Apache Tomcat 7.0.22
Apache Tomcat 7.0.14
Apache Tomcat 7.0.12
Apache Tomcat 7.0.40
Apache Tomcat 7.0.4
Apache Tomcat 7.0.32
Apache Tomcat 7.0.30
Apache Tomcat 7.0.21
Apache Tomcat 7.0.20
Apache Tomcat 7.0.11
Apache Tomcat 7.0.10
Apache Tomcat 7.0.69
Apache Tomcat 7.0.68
Apache Tomcat 7.0.63
Apache Tomcat 7.0.62
Apache Tomcat 7.0.50
Apache Tomcat 7.0.39
Apache Tomcat 7.0.29
Apache Tomcat 7.0.28
Apache Tomcat 7.0.27
Apache Tomcat 7.0.2
Apache Tomcat 7.0.1
7.5
CVSSv2
CVE-2019-0189
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter...
Apache Ofbiz
2 Github repositories available
4
CVSSv2
CVE-2014-2600
Unspecified vulnerability in HP IceWall Identity Manager 4.0 through SP1 and 5.0 and IceWall SSO 10.0 Password Reset Option, when Apache Commons FileUpload is used, allows remote authenticated users to cause a denial of service via unknown vectors....
Hp Icewall Identity Manager 4.0
Hp Icewall Sso Password Reset Option 10.0
Hp Icewall Identity Manager 5.0
NA
CVE-2023-27901
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of...
Jenkins Jenkins
NA
CVE-2023-27900
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in hudson.util.MultipartFormDataParser, allowing attackers to trigger a denial of...
Jenkins Jenkins
7.5
CVSSv2
CVE-2013-2186
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance....
Redhat Jboss Enterprise Brms Platform 5.3.1
Redhat Jboss Enterprise Web Server 1.0.2
Redhat Jboss Enterprise Portal Platform 6.0.0
Redhat Openshift
Redhat Jboss Enterprise Portal Platform 5.2.2
Redhat Jboss Enterprise Portal Platform 4.3.0
Ubuntu Ubuntu 10.04
23 Github repositories available
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-5172
CVE-2023-44023
CVE-2023-30845
elevation of privilege
injection
CVE-2023-43234
CVE-2023-41991
cross-site request forgery
seacms
CVE-2023-5197
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started