Show filters
1,207 Total Results
Displaying 121-130 of 1,207
Sort by:
Attacker Value
Unknown
CVE-2020-19786
Disclosure Date: March 23, 2023 (last updated February 24, 2025)
File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP file.
0
Attacker Value
Unknown
CVE-2023-23707
Disclosure Date: March 23, 2023 (last updated February 24, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Unrestricted Upload of File with Dangerous Type vulnerability in Awsm Innovations Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files allows Stored XSS via upload of SVG and HTML files. This issue affects Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin <= 2.7.1 versions.
0
Attacker Value
Unknown
CVE-2023-1561
Disclosure Date: March 22, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, was found in code-projects Simple Online Hotel Reservation System 1.0. Affected is an unknown function of the file add_room.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-223554 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-1559
Disclosure Date: March 22, 2023 (last updated February 24, 2025)
A vulnerability classified as problematic was found in SourceCodester Storage Unit Rental Management System 1.0. This vulnerability affects unknown code of the file classes/Users.php?f=save. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223552.
0
Attacker Value
Unknown
CVE-2023-1558
Disclosure Date: March 22, 2023 (last updated February 24, 2025)
A vulnerability classified as critical has been found in Simple and Beautiful Shopping Cart System 1.0. This affects an unknown part of the file uploadera.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223551.
0
Attacker Value
Unknown
CVE-2023-28725
Disclosure Date: March 22, 2023 (last updated February 24, 2025)
General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in 20221118.48 and 20230120.44.
0
Attacker Value
Unknown
CVE-2023-1501
Disclosure Date: March 19, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, was found in RockOA 2.3.2. This affects the function runAction of the file acloudCosAction.php.SQL. The manipulation of the argument fileid leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223401 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-1497
Disclosure Date: March 19, 2023 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. It has been rated as critical. This issue affects some unknown processing of the file uploaderm.php. The manipulation of the argument submit leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223397 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-1484
Disclosure Date: March 18, 2023 (last updated February 24, 2025)
A vulnerability was found in xzjie cms up to 1.0.3 and classified as critical. This issue affects some unknown processing of the file /api/upload. The manipulation of the argument uploadFile leads to unrestricted upload. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-223367.
0
Attacker Value
Unknown
CVE-2023-1479
Disclosure Date: March 18, 2023 (last updated February 24, 2025)
A vulnerability classified as critical has been found in SourceCodester Simple Music Player 1.0. Affected is an unknown function of the file save_music.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-223362 is the identifier assigned to this vulnerability.
0