Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
avatar uploader project avatar uploader vulnerabilities and exploits
(subscribe to this query)
356
VMScore
CVE-2014-9155
Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x prior to 6.x-1.2 and 7.x-1.x prior to 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel.
Avatar Uploader Project Avatar Uploader 7.x-1.x-dev
Avatar Uploader Project Avatar Uploader 6.x-1.0
Avatar Uploader Project Avatar Uploader 7.x-1.0
Avatar Uploader Project Avatar Uploader 6.x-1.1
578
VMScore
CVE-2015-2087
Unrestricted file upload vulnerability in the Avatar Uploader module prior to 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.
Avatar Uploader Project Avatar Uploader
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-33545
CVE-2024-35725
CVE-2024-32704
overflow
file upload
CVE-2024-0230
CVE-2024-32705
CVE-2024-23692
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started