Filtered by CWE-434
Total 2500 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-23083 1 Guojusoft 1 Jeecg 2024-08-04 9.8 Critical
Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload".
CVE-2020-23043 1 Air Sender Project 1 Air Sender 2024-08-04 8.8 High
Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted file.
CVE-2020-22755 1 Mingsoft 1 Mcms 2024-08-04 8.8 High
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.
CVE-2020-22722 2 Microsoft, Rapidscada 2 Windows, Rapid Scada 2024-08-04 7.8 High
Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker can obtain admin privileges by placing a malicious .exe file in the application and renaming it ScadaAgentSvc.exe, which would result in executing the binary as NT AUTHORITY\SYSTEM in a Windows operating system. For example, an attacker can plant a reverse shell from a low privileged user account and by restarting the computer, the malicious service will be started as NT AUTHORITY\SYSTEM by giving the attacker full system access to the remote PC.
CVE-2020-22643 1 Feehi 1 Feehi Cms 2024-08-04 7.2 High
Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in, open the administrator image upload page to potentially upload malicious files.
CVE-2020-22721 1 Pnotes.net Project 1 Pnotes.net 2024-08-04 7.8 High
A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary code via the Miscellaneous " External Programs by uploading the malicious .exe file to the external program.
CVE-2020-22249 1 Phplist 1 Phplist 2024-08-04 9.8 Critical
Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which would lead to the remote code execution
CVE-2020-22153 1 Thedaylightstudio 1 Fuel Cms 2024-08-04 9.8 Critical
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.
CVE-2020-22159 1 Evertz 6 3080ipx, 3080ipx Firmware, 7801fc and 3 more 2024-08-04 8.8 High
EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files.
CVE-2020-21786 1 Ibos 1 Ibos 2024-08-04 9.8 Critical
In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php.
CVE-2020-21787 1 Crmeb 1 Crmeb 2024-08-04 9.8 Critical
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.
CVE-2020-21976 1 Newsone Cms Project 1 Newsone Cms 2024-08-04 8.8 High
An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers to webshell and execute arbitrary commands.
CVE-2020-21861 1 Duxcms Project 1 Duxcms 2024-08-04 8.8 High
File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.
CVE-2020-21564 1 Pluck-cms 1 Pluck 2024-08-04 8.8 High
An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.
CVE-2020-21483 1 Jizhicms 1 Jizhicms 2024-08-04 7.2 High
An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file which is later changed to a PHP file.
CVE-2020-21585 1 Emlog 1 Emlog 2024-08-04 9.8 Critical
Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.
CVE-2020-21516 1 Feehi 1 Feehicms 2024-08-04 9.8 Critical
There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.
CVE-2020-21474 1 Nucleuscms 1 Nucleuscms 2024-08-04 9.8 Critical
File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.
CVE-2020-21489 1 Feehi 1 Feehicms 2024-08-04 9.8 Critical
File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component.
CVE-2020-21452 1 Uniview 2 Isc2500-s, Isc2500-s Firmware 2024-08-04 9.8 Critical
An issue was discovered in uniview ISC2500-S. This is an upload vulnerability where an attacker can upload malicious code via /Interface/DevManage/EC.php?cmd=upload