Filtered by CWE-434
Total 4343 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2015-4462 1 Efrontlearning 1 Efront 2025-04-20 N/A
Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for professor.php.
CVE-2015-4463 1 Efrontlearning 1 Efront 2025-04-20 N/A
The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file URL.
CVE-2015-9228 1 Imagely 1 Nextgen Gallery 2025-04-20 N/A
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2017-14346 1 Blog Project 1 Blog 2025-04-20 N/A
upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file.
CVE-2017-15673 1 Cs-cart 1 Cs-cart 2025-04-20 N/A
The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP code via vectors involving a custom page.
CVE-2017-11154 1 Synology 1 Photo Station 2025-04-20 N/A
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to create arbitrary PHP scripts via the type parameter.
CVE-2020-22539 2 Codoforum, Codologic 2 Codoforum, Codoforum 2025-04-18 7.2 High
An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-32161 1 Jizhicms 1 Jizhicms 2025-04-18 9.8 Critical
jizhiCMS 2.5 suffers from a File upload vulnerability.
CVE-2024-48202 1 Thecosy 1 Icecms 2025-04-18 9.8 Critical
icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.
CVE-2023-50692 1 Jizhicms 1 Jizhicms 2025-04-17 8.8 High
File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.
CVE-2024-2599 1 Amss\+\+ Project 1 Amss\+\+ 2025-04-17 9.9 Critical
File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE through webshell, compromising the entire infrastructure.
CVE-2023-52044 1 Std42 1 Elfinder 2025-04-17 9.8 Critical
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.
CVE-2022-46135 1 Aerocms Project 1 Aerocms 2025-04-17 7.2 High
In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and control the web server.
CVE-2023-42248 1 Seling 1 Visual Access Manager 2025-04-17 6.5 Medium
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of the page "common/vam_Sql.php".
CVE-2022-46020 1 Wbce 1 Wbce Cms 2025-04-17 9.8 Critical
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
CVE-2024-46377 2 Mayurik, Sourcecodester 2 Best House Rental Management System, Best House Rental Management System 2025-04-16 9.8 Critical
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.
CVE-2024-33438 1 Cubecart 1 Cubecart 2025-04-16 8 High
File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.
CVE-2024-31615 1 Thinkcmf 1 Thinkcmf 2025-04-16 9.8 Critical
ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.
CVE-2021-27428 1 Ge 38 Multilin B30, Multilin B30 Firmware, Multilin B90 and 35 more 2025-04-16 9.8 Critical
GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade firmware without appropriate privileges. The weakness is assessed, and mitigation is implemented in firmware Version 8.10.
CVE-2021-32961 1 Auvesy-mdt 2 Autosave, Autosave For System Platform 2025-04-16 7.5 High
A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip command and place a malicious .exe file in one of the locations the function looks for and get execution capabilities.