Vulnerabilities (CVE)

Filtered by vendor Projeqtor Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-18924 1 Projeqtor 1 Projeqtor 2020-08-24 6.5 MEDIUM 8.8 HIGH
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the server, with predictable filenames, after a "This file is not a valid image" error message.
CVE-2017-11760 1 Projeqtor 1 Projeqtor 2017-08-09 6.5 MEDIUM 8.8 HIGH
uploadImage.php in ProjeQtOr before 6.3.2 allows remote authenticated users to execute arbitrary PHP code by uploading a .php file composed of concatenated image data and script data, as demonstrated by uploading as an image within the description text area.