VulnSea

CWE-434

CVEs classified under CWE-434, newest first.

232 CVEsRSS

CVE-2021-46116High· 7.2
4y ago

jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall

jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code.

▾ Twilightjpress · jpressEPSS 2.2%via NVD
CVE-2021-46115High· 7.2
4y ago

jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile

jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code.

▾ Twilightjpress · jpressEPSS 1.1%via NVD
CVE-2021-45808High· 8.8
4y ago

jpress v4.2.0 allows users to register an account by default

jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.

▾ Twilightjpress · jpressEPSS 1.3%via NVD
CVE-2021-36582Critical· 9.8
5y ago

In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server

In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and ca…

▾ Midnightkooboo · kooboo_cmsEPSS 1.5%via NVD
CVE-2021-36581Critical· 9.8
5y ago

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

▾ Midnightkooboo · kooboo_cmsEPSS 1.4%via NVD
CVE-2020-26678High· 8.8
5y ago

vFairs 3.3 is affected by Remote Code Execution

vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execut…

▾ Twilightvfairs · vfairsEPSS 1.8%via NVD
CVE-2021-29022Medium· 5.3
5y ago

In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.

In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.

▾ Sunlitinvoiceplane · invoiceplaneEPSS 1.1%via NVD
CVE-2021-20022High· 7.2CISA KEV
5y ago

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

▾ Abyssalsonicwall · email_securityEPSS 17%via NVD
CVE-2020-3436High· 8.6
5y ago

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files to specific folder…

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files to specific folder…

▾ Twilightcisco · adaptive_security_applianceEPSS 1.9%via NVD
CVE-2020-25515High· 7.8
6y ago

Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http://<site>/lms/index.php?page=books.

Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http://<site>/lms/index.php?page=books.

▾ Twilightsimple_library_management_system_project · simple_library_management_systemEPSS 0.51%via NVD
CVE-2020-1112High· 8.5
6y ago

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content. An attacker who successfully exploited this vulnerability could upload restric…

▾ Twilightmicrosoft · windows_10EPSS 3.3%via NVD
CVE-2020-1102High· 8.8PoC
6y ago

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the c…

▾ Midnightmicrosoft · sharepoint_enterprise_serverEPSS 5.2%via NVD
CVE-2020-1024High· 8.8
6y ago

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the c…

▾ Twilightmicrosoft · sharepoint_enterprise_serverEPSS 3.7%via NVD
CVE-2020-1023High· 8.8
6y ago

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the c…

▾ Twilightmicrosoft · sharepoint_enterprise_serverEPSS 3.7%via NVD
CVE-2019-19634Critical· 9.8PoC
6y ago

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.

▾ Abyssalverot_project · verotEPSS 4.2%via NVD
CVE-2019-19576Critical· 9.8PoC
6y ago

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

▾ Abyssalverot_project · verotEPSS 26%via NVD
CVE-2019-14748Medium· 5.4PoC
7y ago

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implement…

▾ Twilightenhancesoft · osticketEPSS 2.7%via NVD
CVE-2019-10869High· 8.1PoC
7y ago

Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated)

Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the…

▾ Midnightninjaforms · ninja_forms_file_uploadsEPSS 8.0%via NVD
CVE-2018-9206Critical· 9.8⚠ ExploitedPoC
7y ago

Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

▾ Abyssaljquery_file_upload_project · jquery_file_uploadEPSS 97%via NVD
CVE-2017-12617High· 8.1CISA KEVPoC
8y ago

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possib…

▾ Abyssalapache · tomcatEPSS 100%via NVD
CVE-2017-12615High· 8.1CISA KEVPoC
9y ago

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted requ…

▾ Abyssalapache · tomcatEPSS 100%via NVD
CVE-2017-11357Critical· 9.8CISA KEVPoC
9y ago

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

▾ Hadalprogress · telerik_ui_for_asp.net_ajaxEPSS 78%via NVD
CWE-434 vulnerabilities (CVEs) — page 8 · VulnSea