Show filters
275 Total Results
Displaying 11-20 of 275
Sort by:
Attacker Value
Unknown

CVE-2021-27198

Disclosure Date: February 26, 2021 (last updated February 22, 2025)
An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI. This application is written in Java and is thus cross-platform. The Windows installation runs as SYSTEM, which means that exploitation gives one Administrator privileges on the target system.
Attacker Value
Unknown

CVE-2020-36079

Disclosure Date: February 26, 2021 (last updated February 22, 2025)
Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder box, and then drag and drop files into the Files(elFinder) portion of the UI. This can, for example, place a .php file in the server's uploaded/ directory. NOTE: the vendor disputes this because exploitation can only be performed by an admin who has "lots of other possibilities to harm a site.
Attacker Value
Unknown

CVE-2021-20659

Disclosure Date: February 24, 2021 (last updated February 22, 2025)
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code.
Attacker Value
Unknown

CVE-2020-7847

Disclosure Date: February 23, 2021 (last updated February 22, 2025)
The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affects: pTIME NAS 1.4.36.
Attacker Value
Unknown

CVE-2021-3120

Disclosure Date: February 22, 2021 (last updated February 22, 2025)
An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. In order to exploit this vulnerability, an attacker must be able to place a valid Gift Card product into the shopping cart. An uploaded file is placed at a predetermined path on the web server with a user-specified filename and extension. This occurs because the ywgc-upload-picture parameter can have a .php value even though the intention was to only allow uploads of Gift Card images.
Attacker Value
Unknown

CVE-2021-27513

Disclosure Date: February 22, 2021 (last updated February 22, 2025)
The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."
Attacker Value
Unknown

CVE-2021-26809

Disclosure Date: February 17, 2021 (last updated February 22, 2025)
PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.
Attacker Value
Unknown

CVE-2021-25780

Disclosure Date: February 17, 2021 (last updated February 22, 2025)
An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote attacker to upload content to the server, including PHP files, which could result in command execution and obtaining a shell.
Attacker Value
Unknown

CVE-2021-22858

Disclosure Date: February 17, 2021 (last updated February 22, 2025)
Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions.
Attacker Value
Unknown

CVE-2020-4955

Disclosure Date: February 12, 2021 (last updated February 22, 2025)
IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter validation. By creating an unspecified servlet request with specially crafted input parameters, an attacker could exploit this vulnerability to load a malicious .dll with elevated privileges. IBM X-Force ID: 192155.