Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
arbitrary vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2021-26918
The ProBot bot through 2021-02-08 for Discord might allow malicious users to interfere with the intended purpose of the "Send an image when a user joins the server" feature (or possibly have unspecified other impact) because the uploader web service allows double extens...
Probot Bot
435
VMScore
CVE-2007-5278
Zomplog 3.8.1 and previous versions stores potentially sensitive information under the web root with insufficient access control, which allows remote malicious users to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct reque...
Zomplog Zomplog 3.8.1
1 EDB exploit
655
VMScore
CVE-2017-17874
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.
Vanguard Project Marketplace Digital Products Php 1.4.0
1 EDB exploit
505
VMScore
CVE-2008-4913
Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and previous versions allows remote malicious users to delete arbitrary files via a .. (dot dot) in the delete parameter.
Lokicms Lokicms 0.1.0
Lokicms Lokicms
Lokicms Lokicms 0.3.2b1
Lokicms Lokicms 0.3.1b2
Lokicms Lokicms 0.2.0
Lokicms Lokicms 0.1.0rc1
Lokicms Lokicms 0.3.1b1
Lokicms Lokicms 0.3.0
1 EDB exploit
655
VMScore
CVE-2008-3093
Unrestricted file upload vulnerability in ImperialBB 2.3.5 and previous versions allows remote authenticated users to upload and execute arbitrary PHP code by placing a .php filename in the Upload_Avatar parameter and sending the image/gif content type.
Phplizardo Imperialbb
1 EDB exploit
1000
VMScore
CVE-1999-1479
The textcounter.pl by Matt Wright allows remote malicious users to execute arbitrary commands via shell metacharacters.
Matt Wright Textcounter 1.2
1 EDB exploit
755
VMScore
CVE-2007-5230
admin/upload_files.php in Zomplog 3.8.1 and previous versions does not check for administrative credentials, which allows remote malicious users to perform administrative actions via a direct request. NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231.
Zomplog Zomplog 3.7.6
Zomplog Zomplog 3.8
Zomplog Zomplog 3.8.1
Zomplog Zomplog 3.7
1 EDB exploit
655
VMScore
CVE-2017-14839
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
Teamworktec Photo Fusion -
1 EDB exploit
505
VMScore
CVE-2014-9261
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote malicious users to read arbitrary files via a .. (dot dot) in the path parameter to index.php.
Codologic Codoforum 2.5.1
1 EDB exploit
NA
CVE-2014-92611
Codoforum version 2.5.1 suffers from an arbitrary file download vulnerability.
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »