Vulnerabilities (CVE)

Filtered by CWE-434
Total 2654 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-28165 1 Easycorp 1 Zentao 2024-11-21 7.5 HIGH 9.8 CRITICAL
The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function.
CVE-2020-28140 1 Online Clothing Store Project 1 Online Clothing Store 2024-11-21 7.5 HIGH 9.8 CRITICAL
SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Products.php.
CVE-2020-28136 1 Phpgurukul 1 Tourism Management System 2024-11-21 6.5 MEDIUM 8.8 HIGH
An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.
CVE-2020-28130 1 Online Library Management System Project 1 Online Library Management System 2024-11-21 10.0 HIGH 9.8 CRITICAL
An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code execution via admin/borrower/index.php?view=add because .php files can be uploaded to admin/borrower/photos (under the web root).
CVE-2020-28088 1 Jeecg 1 Jeecg Boot 2024-11-21 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.
CVE-2020-28072 1 Alumni Management System Project 1 Alumni Management System 2024-11-21 6.5 MEDIUM 7.2 HIGH
A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.
CVE-2020-28063 1 Articlecms Project 1 Articlecms 2024-11-21 7.5 HIGH 9.8 CRITICAL
A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.
CVE-2020-28062 1 Hisiphp 1 Hisiphp 2024-11-21 6.5 MEDIUM 7.2 HIGH
An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote malicious user execute arbitrary code.
CVE-2020-27956 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execution via admin/index.php?page=manage_car because .php files can be uploaded to admin/assets/uploads/ (under the web root).
CVE-2020-27461 1 Seopanel 1 Seopanel 2024-11-21 6.5 MEDIUM 8.8 HIGH
A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the Settings Panel>Import website function.
CVE-2020-27397 1 Projectworlds 1 Online Matrimonial Project 2024-11-21 6.5 MEDIUM 8.8 HIGH
Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain remote code execution (RCE) on the Hosting web server via uploading a maliciously crafted PHP file.
CVE-2020-27387 1 Horizontcms Project 1 Horizontcms 2024-11-21 6.5 MEDIUM 8.8 HIGH
An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename function to provide the payload (which will receive a random name on the server) with the PHP extension, and finally executing the PHP file via an HTTP GET request to /storage/<php_file_name>. NOTE: the vendor has patched this while leaving the version number at 1.0.0-beta.
CVE-2020-27386 1 Flexdotnetcms Project 1 Flexdotnetcms 2024-11-21 6.5 MEDIUM 8.8 HIGH
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or the FileManager's rename function (in v1.5.7 and prior) to rename the file to an executable extension (e.g., ASP), and finally executing the file via an HTTP GET request to /<path_to_file>.
CVE-2020-26828 1 Sap 1 Disclosure Management 2024-11-21 5.5 MEDIUM 6.4 MEDIUM
SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of specific file type. In some file types it is possible to enter formulas which can call external applications or execute scripts. The execution of a payload (script) on target machine could be used to steal and modify the data available in the spreadsheet
CVE-2020-26826 1 Sap 1 Netweaver Application Server Java 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upload.
CVE-2020-26820 1 Sap 1 Netweaver Application Server Java 2024-11-21 9.0 HIGH 7.2 HIGH
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then use a separate mechanism to execute OS commands through the uploaded file leading to Privilege Escalation and completely compromise the confidentiality, integrity and availability of the server operating system and any application running on it.
CVE-2020-26804 1 Sapplica 1 Sentrifugo 2024-11-21 6.5 MEDIUM 8.8 HIGH
In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with the shared announcements. This "Upload Attachment" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this functionality and control the server.
CVE-2020-26803 1 Sapplica 1 Sentrifugo 2024-11-21 6.5 MEDIUM 8.8 HIGH
In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this functionality and control the server.
CVE-2020-26678 1 Vfairs 1 Vfairs 2024-11-21 6.5 MEDIUM 8.8 HIGH
vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execution.
CVE-2020-26629 1 Phpgurukul 1 Hospital Management System 2024-11-21 N/A 9.8 CRITICAL
A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server.