Show filters
350 Total Results
Displaying 21-30 of 350
Sort by:
Attacker Value
Unknown

CVE-2020-21005

Disclosure Date: June 03, 2021 (last updated February 22, 2025)
WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is controllable, the user can modify the upload file type to get webshell.
Attacker Value
Unknown

CVE-2020-35442

Disclosure Date: June 02, 2021 (last updated February 22, 2025)
FDCMS (also known as Fangfa Content Management System) 4.0 allows remote attackers to get a webshell in the background via Front/lib/Action/FindexAction.class.php.
Attacker Value
Unknown

CVE-2021-24311

Disclosure Date: June 01, 2021 (last updated February 22, 2025)
The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users.
Attacker Value
Unknown

CVE-2021-29092

Disclosure Date: May 31, 2021 (last updated February 22, 2025)
Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified vectors.
Attacker Value
Unknown

CVE-2021-31703

Disclosure Date: May 29, 2021 (last updated February 22, 2025)
Frontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by any client user.
Attacker Value
Unknown

CVE-2020-26678

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execution.
Attacker Value
Unknown

CVE-2020-23765

Disclosure Date: May 21, 2021 (last updated February 22, 2025)
A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe plugins to upload a backup file and control the server.
Attacker Value
Unknown

CVE-2021-32630

Disclosure Date: May 20, 2021 (last updated February 22, 2025)
Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.0.4, there is an authenticated RCE via .phar file upload. A php web shell can be uploaded via the Documents & Files upload feature. Someone with upload permissions could rename the php shell with a .phar extension, visit the file, triggering the payload for a reverse/bind shell. This can be mitigated by excluding a .phar file extension to be uploaded (like you did with .php .phtml .php5 etc). The vulnerability is patched in version 4.0.4.
Attacker Value
Unknown

CVE-2021-27459

Disclosure Date: May 20, 2021 (last updated February 22, 2025)
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, which an attacker could utilize to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-20721

Disclosure Date: May 20, 2021 (last updated February 22, 2025)
KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the file contains PHP scripts, arbitrary code may be executed.