Brian Cardinale reported a file upload directory traversal vulnerability that affects the AjaxControlToolkit prior to version 15.1. On a poorly configured web server this vulnerability can lead to remote code execution. The flaw was introduced in version 7.429 which was released on April 30, 2013. The latest vulnerable version is 7.1213.
List of vulnerable versions:
It's recommended to upgrade to the latest version of AjaxControlToolkit.
CVE-2015-4670: Directory Traversal to Remote Code Execution in AjaxControlToolkit
WordPress Plugin WPS Bidouille Multiple Vulnerabilities (1.12.2)
Drupal Core 8.5.x Remote Code Execution (8.5.0 - 8.5.10)
Drupal Remote Code Execution (SA-CORE-2018-002)
WordPress Plugin All in One SEO-Best WordPress SEO-Easily Improve SEO Rankings & Increase Traffic Remote Code Execution (184.108.40.206)
WordPress Plugin WordPress Shortcodes-Shortcodes Ultimate Remote Code Execution (5.0.0)