exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 948 RSS Feed

File Upload Files

Gold Filled CRM 2.0 Arbitrary File Upload
Posted Jan 12, 2023
Authored by indoushka

Gold Filled CRM version 2.0 suffers from an unauthenticated arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 7df5256a62f4b26f1e4415c585d3fa307a8092cdea4dec86c2b611cd1e38214d
ERPGo SaaS CRM 3.3 Arbitrary File Upload
Posted Jan 11, 2023
Authored by indoushka

ERPGo SaaS CRM version 3.3 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 75550497f441c15436243b166bf836846ad5f220742342f795cbab8cded44902
Roxy Fileman 1.4.6 Remote Shell Upload
Posted Nov 21, 2022
Authored by Hadi Mene

Roxy Fileman versions 1.4.6 and below remote shell upload proof of concept exploit.

tags | exploit, remote, shell, proof of concept, file upload
advisories | CVE-2022-40797
SHA-256 | 16a9c59173c82b869a340397a5e68377531e0e0f9be9781793142e4f47786e1b
WordPress Kaswara Modern WPBakery Page Builder 3.0.1 File Upload
Posted Jul 14, 2022
Site wordfence.com

WordPress Kaswara Modern WPBakery Page Builder plugin versions 3.0.1 and below suffer from an arbitrary file upload vulnerability.

tags | advisory, arbitrary, file upload
advisories | CVE-2021-24284
SHA-256 | cda2f52f6b43d9a253406aa83b3d7934624dc39c1c6c8f9a0240d741e6ae5fa3
PrestaShop 1.7.6.7 Cross Site Scripting
Posted Jul 14, 2022
Authored by Priyanka Samak

PrestaShop version 1.7.6.7 suffers from a cross site scripting vulnerability via the file upload functionality.

tags | exploit, xss, file upload
advisories | CVE-2020-21967
SHA-256 | fd8caaa9cec4a7055dd238f60bb28982f0acab62605c410f5808fff8eccaa174
Multi Language Pharmacy Management System 1.0 Shell Upload
Posted Jun 20, 2022
Authored by Emirhan Kurt | Site metasploit.com

This Metasploit module exploits the file upload vulnerability of Multi Language Pharmacy Management System to achieve remote code execution.

tags | exploit, remote, code execution, file upload
SHA-256 | 742456930e5e52c2ee76502248a99373d271bc23c86a2afc2380664719fcc4cb
e107 CMS 3.2.1 Arbitrary File Upload / Cross Site Scripting
Posted May 11, 2022
Authored by Hubert Wojciechowski

e107 CMS version 3.2.1 suffers from cross site scripting and arbitrary file upload vulnerabilities that can allow for a shell upload.

tags | exploit, arbitrary, shell, vulnerability, xss, file upload
SHA-256 | 3ae8caceae21f93d20493507ca607ad9781c300dc643e858c7c2ac8aa48b23b5
WordPress Advanced Uploader 4.2 Shell Upload
Posted May 11, 2022
Authored by Roel van Beurden

WordPress Advanced Uploader plugin versions 4.2 and below suffer from a remote shell upload vulnerability.

tags | exploit, remote, shell, file upload
advisories | CVE-2022-1103
SHA-256 | d6da47e9cfa89f863bdbab26f72fb5536450efbf87365b7899f665f69f1edd2a
ImpressCMS 1.4.4 Arbitrary File Upload
Posted May 11, 2022
Authored by Unsal Furkan Harani

ImpressCMS version 1.4.4 suffers from an arbitrary file upload due to a weak blacklisting methodology for file extensions.

tags | exploit, arbitrary, file upload
SHA-256 | e3a1d424f71f1feb571e0ac4b2912e399c1c124ebdfb5d9e83276acd5816f7e8
TLR-2005KSH Arbitrary File Upload
Posted May 11, 2022
Authored by Ahmed Alroky

TLR-2005KSH suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
advisories | CVE-2021-45428
SHA-256 | f7ccc88ff2a331dfcd6837d903e8a8b9647905703b086149bc856a1f4d52c2d9
WSO Arbitrary File Upload / Remote Code Execution
Posted May 2, 2022
Authored by Orange Tsai, wvu, hakivvi, Jack Heysel | Site metasploit.com

This Metasploit module abuses a vulnerability in certain WSO2 products that allow unrestricted file upload with resultant remote code execution. This affects WSO2 API Manager 2.2.0 and above through 4.0.0; WSO2 Identity Server 5.2.0 and above through 5.11.0; WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, and 5.6.0; WSO2 Identity Server as Key Manager 5.3.0 and above through 5.10.0; and WSO2 Enterprise Integrator 6.2.0 and above through 6.6.0.

tags | exploit, remote, code execution, file upload
advisories | CVE-2022-29464
SHA-256 | 7bdab9b3101da4ba2df8ff1f6a558171e4d8a503d4d44bcbaf0347587fa69a4d
PHPGurukul Zoo Management System 1.0 Shell Upload
Posted Apr 8, 2022
Authored by D4rkP0w4r | Site github.com

PHPGurukul Zoo Management System version 1.0 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell, file upload
advisories | CVE-2022-27351
SHA-256 | dca1f178a16cf53e52736d7b787820a9fbabb32e64848116ca5fc2680795d6d7
Roxy File Manager 1.4.5 PHP File Upload Restriction Bypass
Posted Apr 4, 2022
Authored by Adam Shebani

Roxy File Manager version 1.4.5 proof of concept exploit for a PHP file upload restriction bypass vulnerability.

tags | exploit, php, proof of concept, bypass, file upload
advisories | CVE-2018-20525
SHA-256 | 56429affeb38a91070ee24b0aaf512970594ce033504501832983da83e9dea5a
Foxit PDF Editor (iOS) 11.3.1 Arbitrary File Upload
Posted Mar 24, 2022
Authored by Saud Alenazi

Foxit PDF Editor (iOS) version 11.3.1 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
systems | ios
SHA-256 | eee6585def5e7c7d4e32865c6af95620ceb8365f388cac02687c0e833289acfa
Ubuntu Security Notice USN-5269-1
Posted Feb 3, 2022
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5269-1 - Keryn Knight discovered that Django incorrectly handled certain template tags. A remote attacker could possibly use this issue to perform a cross-site scripting attack. Alan Ryan discovered that Django incorrectly handled file uploads. A remote attacker could possibly use this issue to cause Django to hang, resulting in a denial of service.

tags | advisory, remote, denial of service, xss, file upload
systems | linux, ubuntu
advisories | CVE-2022-22818, CVE-2022-23833
SHA-256 | 44ead4d24055dc9998855e1e79daf13648af011234c8ab7db00a1edd78b0a0fc
Landa Driving School Management System 2.0.1 Arbitrary File Upload
Posted Jan 18, 2022
Authored by Sohel Yousef

Landa Driving School Management System version 2.0.1 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 1e684f4bf2740af67139b537773580e9c66f842543ab7922604bfaaf83b03922
ManageEngine ServiceDesk Plus Remote Code Execution
Posted Dec 28, 2021
Authored by wvu, Y4er | Site metasploit.com

This Metasploit module exploits CVE-2021-44077, an unauthenticated remote code execution vulnerability in ManageEngine ServiceDesk Plus, to upload an EXE (msiexec.exe) and execute it as the SYSTEM account. Note that build 11305 is vulnerable to the authentication bypass but not the file upload. The module will check for an exploitable build.

tags | exploit, remote, code execution, file upload
advisories | CVE-2021-44077
SHA-256 | 244ae2538bc9ec8f90e308561999a95ddf997764203cb31dbd2e32b039b73273
AbanteCart Arbitrary File Upload / Cross Site Scripting
Posted Dec 14, 2021
Authored by Ian Chong, Daniel Teo | Site sec-consult.com

AbanteCart e-commerce platform versions prior to 1.3.2 suffer from cross site scripting and file upload vulnerabilities.

tags | exploit, vulnerability, xss, file upload
advisories | CVE-2021-42050, CVE-2021-42051
SHA-256 | 1d18e94320294ca7bb9c057c9b6c90c647799d170ceda260890a08b559774f32
Online Learning System 2.0 Remote Code Execution
Posted Nov 16, 2021
Authored by djebbaranon

Online Learning System version 2.0 remote code execution exploit that leverages SQL injection, authentication bypass, and file upload vulnerabilities.

tags | exploit, remote, vulnerability, code execution, sql injection, file upload
advisories | CVE-2021-42580
SHA-256 | e13c0631f420057004b808a4af6435c2db1224089738b4762896aa208c6c4df8
GitLab Unauthenticated Remote ExifTool Command Injection
Posted Nov 4, 2021
Authored by William Bowling, jbaines-r7 | Site metasploit.com

This Metasploit module exploits an unauthenticated file upload and command injection vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE). The patched versions are 13.10.3, 13.9.6, and 13.8.8. Exploitation will result in command execution as the git user.

tags | exploit, file upload
advisories | CVE-2021-22204, CVE-2021-22205
SHA-256 | 674d3772ec48b70f0ba624c93a36ffde9a6d313b18359aa19702fc270257ff56
Alchemy CMS 6.0.0 Arbitrary File Upload
Posted Oct 13, 2021
Authored by Abdulrahman

Alchemy CMS versions 2.x through 6.0.0 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 6bd3ac8df72360c8b2283948f43f6eca26db0404536d856dac8456679bf76b08
VMware vCenter Server Analytics (CEIP) Service File Upload
Posted Oct 7, 2021
Authored by VMware, Derek Abdine, wvu, Sergey Gerasimov, George Noseevich | Site metasploit.com

This Metasploit module exploits a file upload in VMware vCenter Server's analytics/telemetry (CEIP) service to write a system crontab and execute shell commands as the root user. Note that CEIP must be enabled for the target to be exploitable by this module. CEIP is enabled by default.

tags | exploit, shell, root, file upload
advisories | CVE-2021-22005
SHA-256 | 036b2591e4ef8beb3558c821f06ea5bf7c27f8226edd7019163d2a719de158ac
College Management System 1.0 Arbitrary File Upload
Posted Oct 4, 2021
Authored by Abdulrahman

College Management System version 1.0 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 86c8805556c5e66a65a17ebcb0557527109d4682af2a0bb382e6b163bb6ceb14
Phpwcms 1.9.30 Cross Site Scripting
Posted Oct 1, 2021
Authored by Okan Kurtulus

Phpwcms version 1.9.30 suffers from a cross site scripting vulnerability via the file upload functionality.

tags | exploit, xss, file upload
SHA-256 | b13080fa702d0a623b11c613c2d06c2c1b46321813ade15e2e32f9ac9fab0c42
ECOA Building Automation System Path Traversal / Arbitrary File Upload
Posted Sep 10, 2021
Authored by Neurogenesia | Site zeroscience.mk

ECOA building automation systems suffer from path traversal and arbitrary file upload vulnerabilities. Many versions are affected.

tags | exploit, arbitrary, vulnerability, file upload
SHA-256 | ea7f9bd9279b87a7dac72d39679684829a62542b790b1b70e36bca9e2ed2428b
Page 1 of 38
Back12345Next

File Archive:

February 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    11 Files
  • 2
    Feb 2nd
    9 Files
  • 3
    Feb 3rd
    5 Files
  • 4
    Feb 4th
    0 Files
  • 5
    Feb 5th
    0 Files
  • 6
    Feb 6th
    0 Files
  • 7
    Feb 7th
    0 Files
  • 8
    Feb 8th
    0 Files
  • 9
    Feb 9th
    0 Files
  • 10
    Feb 10th
    0 Files
  • 11
    Feb 11th
    0 Files
  • 12
    Feb 12th
    0 Files
  • 13
    Feb 13th
    0 Files
  • 14
    Feb 14th
    0 Files
  • 15
    Feb 15th
    0 Files
  • 16
    Feb 16th
    0 Files
  • 17
    Feb 17th
    0 Files
  • 18
    Feb 18th
    0 Files
  • 19
    Feb 19th
    0 Files
  • 20
    Feb 20th
    0 Files
  • 21
    Feb 21st
    0 Files
  • 22
    Feb 22nd
    0 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close