Show filters
970 Total Results
Displaying 71-80 of 970
Sort by:
Attacker Value
Unknown

CVE-2022-41539

Disclosure Date: October 14, 2022 (last updated February 24, 2025)
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-41538

Disclosure Date: October 14, 2022 (last updated February 24, 2025)
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Management-PHP/admin/photos_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-41534

Disclosure Date: October 13, 2022 (last updated February 24, 2025)
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-41533

Disclosure Date: October 13, 2022 (last updated February 24, 2025)
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-3458

Disclosure Date: October 12, 2022 (last updated February 24, 2025)
A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /employeeview.php of the component Image File Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-210559.
Attacker Value
Unknown

CVE-2022-41406

Disclosure Date: October 12, 2022 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-40921

Disclosure Date: October 12, 2022 (last updated February 24, 2025)
DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php.
Attacker Value
Unknown

CVE-2022-40777

Disclosure Date: October 11, 2022 (last updated February 24, 2025)
Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a /admin/temp/surveys/ URI. NOTE: this issue exists because of an incomplete fix for CVE-2018-19550.
Attacker Value
Unknown

CVE-2022-42044

Disclosure Date: October 11, 2022 (last updated February 24, 2025)
The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.
Attacker Value
Unknown

CVE-2022-42043

Disclosure Date: October 11, 2022 (last updated February 24, 2025)
The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.