Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
avatar vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2002-2346
phpBB 2.0 up to and including 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote malicious users to obtain client IP addresses.
Phpbb Phpbb 2.0
Phpbb Phpbb 2.0.2
Phpbb Phpbb 2.0.1
Phpbb Phpbb 2.0.3
9.8
CVSSv3
CVE-2021-44093
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell
Zrlog Zrlog 2.2.2
NA
CVE-2007-1129
Multiple unrestricted file upload vulnerabilities in MTCMS 3.2 allow remote malicious users to upload and execute files via (1) an avatar upload in an add_down action, or (2) an add_link action.
Mtcms Mtcms 3.2
8.8
CVSSv3
CVE-2020-12854
A remote code execution vulnerability was identified in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can invoke code execution upon uploading a carefully crafted JPEG file as part of the profile avatar.
Seczetta Neprofile 3.3.11
5.8
CVSSv3
CVE-2019-11767
Server side request forgery (SSRF) in phpBB prior to 3.2.6 allows checking for the existence of files and services on the local network of the host through the remote avatar upload function.
Phpbb Phpbb
8.8
CVSSv3
CVE-2019-12099
In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during avatar upload.
Php-fusion Php-fusion
NA
CVE-2009-1070
Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 up to and including 1.6.6, and possibly earlier versions, allows remote malicious users to inject arbitrary web script or HTML via the avatar parameter.
Expressionengine Expressionengine 1.6.4
Expressionengine Expressionengine 1.6.5
Expressionengine Expressionengine 1.6.6
1 EDB exploit
NA
CVE-2004-2711
Multiple buffer overflows in Gyach Enhanced (Gyach-E) prior to 1.0.2 allow remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "avatar retrieval."
Phrozensmoke Gyach Enhanced
5.4
CVSSv3
CVE-2021-3539
EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 6.1.7 of the product.
Espocrm Espocrm
5.4
CVSSv3
CVE-2021-36803
Akaunting version 2.1.12 and previous versions suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 2.1.13 of the product.
Akaunting Akaunting
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »