Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Avatar Uploader Project Subscribe
Filtered by product Avatar Uploader
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-2087 1 Avatar Uploader Project 1 Avatar Uploader 2015-02-27 6.5 MEDIUM N/A
Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.
CVE-2014-9155 1 Avatar Uploader Project 1 Avatar Uploader 2014-12-05 4.0 MEDIUM N/A
Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel.