Show filters
1,306 Total Results
Displaying 131-140 of 1,306
Sort by:
Attacker Value
Unknown
CVE-2023-32686
Disclosure Date: May 27, 2023 (last updated February 25, 2025)
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versions of Kiwi TCMS had introduced upload validators in order to prevent potentially dangerous files from being uploaded. The upload validation checks were not robust enough which left the possibility of an attacker to circumvent them and upload a potentially dangerous file. Exploiting this flaw, a combination of files could be uploaded so that they work together to circumvent the existing Content-Security-Policy and allow execution of arbitrary JavaScript in the browser. This issue has been patched in version 12.3.
0
Attacker Value
Unknown
CVE-2023-22504
Disclosure Date: May 25, 2023 (last updated February 25, 2025)
Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.
0
Attacker Value
Unknown
CVE-2023-2888
Disclosure Date: May 25, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&_noCache=0.1683794968. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-229953 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-29721
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution.
0
Attacker Value
Unknown
CVE-2023-28409
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file.
0
Attacker Value
Unknown
CVE-2023-27397
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
0
Attacker Value
Unknown
CVE-2023-31689
Disclosure Date: May 22, 2023 (last updated February 25, 2025)
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. It can write arbitrary strings into custom file names and upload any files, and write malicious code to execute scripts to trigger command execution.
0
Attacker Value
Unknown
CVE-2023-2712
Disclosure Date: May 20, 2023 (last updated February 25, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server.This issue affects Rental Module: before 23.05.15.
Attacker Value
Unknown
CVE-2023-30333
Disclosure Date: May 18, 2023 (last updated February 25, 2025)
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file.
0
Attacker Value
Unknown
CVE-2023-2776
Disclosure Date: May 17, 2023 (last updated February 25, 2025)
A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-229282 is the identifier assigned to this vulnerability.
0