Show filters
1,116 Total Results
Displaying 111-120 of 1,116
Sort by:
Attacker Value
Unknown

CVE-2022-42287

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering.
Attacker Value
Unknown

CVE-2023-0257

Disclosure Date: January 12, 2023 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /fos/admin/index.php?page=menu of the component Menu Form. The manipulation of the argument Image with the input <?php system($_GET['c']); ?> leads to unrestricted upload. The attack can be launched remotely. The identifier VDB-218185 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-46610

Disclosure Date: January 10, 2023 (last updated February 24, 2025)
72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-44036

Disclosure Date: January 03, 2023 (last updated February 24, 2025)
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it."
Attacker Value
Unknown

CVE-2022-48194

Disclosure Date: December 30, 2022 (last updated February 24, 2025)
TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.
Attacker Value
Unknown

CVE-2022-43436

Disclosure Date: December 30, 2022 (last updated February 24, 2025)
The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker authenticated as a general user can upload and execute arbitrary files, to manipulate system or disrupt service.
Attacker Value
Unknown

CVE-2022-45427

Disclosure Date: December 27, 2022 (last updated February 24, 2025)
Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can upload arbitrary files.
Attacker Value
Unknown

CVE-2022-4732

Disclosure Date: December 27, 2022 (last updated February 24, 2025)
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.
Attacker Value
Unknown

CVE-2022-45896

Disclosure Date: December 25, 2022 (last updated February 24, 2025)
Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/ProcessUpload2. This leads to remote code execution.
Attacker Value
Unknown

CVE-2022-4665

Disclosure Date: December 23, 2022 (last updated February 24, 2025)
Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.