exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 987 RSS Feed

File Upload Files

WordPress User Registration 3.0.2 Arbitrary File Upload
Posted Jul 12, 2023
Authored by Lana Codes | Site wordfence.com

The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hard-coded encryption key and missing file type validation on the ur_upload_profile_pic function in versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with subscriber-level capabilities or above to upload arbitrary files on the affected site's server which may make remote code execution possible. This was partially patched in version 3.0.2 and fully patched in version 3.0.2.1.

tags | exploit, remote, arbitrary, code execution, file upload
advisories | CVE-2023-3342
SHA-256 | 617e7a31e8613b2fc41dfb20282c61f763065187b026a8188f18e87a77f289a5
Architect HTML And Site Builder 2.2.3 File Upload
Posted Jul 12, 2023
Authored by indoushka

Architect HTML and Site Builder version 2.2.3 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | e39afa37fd4029d2a1d6029ed16c4ba2ee567a5ba7b61b45d8601e4c7d4ba3ab
Alumni Club Management Tools 2.2.7 SQL Injection / Arbitrary File Upload
Posted Jul 2, 2023
Authored by indoushka

Alumni Club Management Tools version 2.2.7 suffers from file upload and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection, file upload
SHA-256 | 1c2184b26be39e09d9396589fc1970fe7145e1f2ce96dcf537d2c8dfd51194c5
MagicAI 1.55R Cross Site Scripting
Posted Jun 27, 2023
Authored by CraCkEr

MagicAI version 1.55R suffers from a persistent cross site scripting vulnerability via a file upload.

tags | exploit, xss, file upload
SHA-256 | f4d106d7a59e4b426baf267d2bfbc5e19be78391b0f2498637e74b343fb4f208
Advanced Form Builder 2.0 Arbitrary File Upload
Posted Jun 26, 2023
Authored by indoushka

Advanced Form Builder version 2.0 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 0fb127a4e4574a26de1bea5b616d506f4efb9d4344b1aa51b865f10ae956b4d0
Online Art Gallery Project 1.0 Arbitrary File Upload
Posted Jun 16, 2023
Authored by Ramil Mustafayev

Online Art Gallery Project version 1.0 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | ab0a3852329b276ac8c81bd14314d1b572e682c349a076a46846217ecf3422d7
Teachers Record Management System 1.0 Validation Bypass
Posted Jun 14, 2023
Authored by AFFAN AHMED

Teachers Record Management System version 1.0 suffers from file upload validation bypass vulnerability.

tags | exploit, bypass, file upload
advisories | CVE-2023-3187
SHA-256 | e55edf3ad86e1cd11b6b01476b398e215f92844b97799ddf06369d679ceeee36
Acelle Email Marketing 4.0.25 Arbitrary File Upload
Posted Jun 9, 2023
Authored by indoushka

Acelle Email Marketing version 4.0.25 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 42a060ff82cd1846f13603b5df42ab433514a56f42b104907918548c7a47ce86
Acelle Email Marketing 3.0.15 Arbitrary File Upload
Posted Jun 1, 2023
Authored by indoushka

Acelle Email Marketing version 1.0 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 8ab91b141d2a757f5c8139e68bc3122becbc9e84709fafd036525d8dda27931b
Serenity / StartSharp Software File Upload / XSS / User Enumeration / Reusable Tokens
Posted May 30, 2023
Authored by Fabian Densborn | Site sec-consult.com

Serenity and StartSharp Software versions prior to 6.7.1 suffer from file upload to cross site scripting, user enumeration, and reusable password reset token vulnerabilities.

tags | exploit, vulnerability, xss, file upload
advisories | CVE-2023-31285, CVE-2023-31286, CVE-2023-31287
SHA-256 | 0c6c4576c7182cef60f1720011b706cffbe6a3ce7cde23ea97cdccf7a4dc0430
Kiddoware Kids Place Parental Control Android App 3.8.49 XSS / CSRF / File Upload
Posted May 16, 2023
Authored by Fabian Densborn, Bernhard Grundling | Site sec-consult.com

Kiddoware Kids Place Parental Control Android App versions 3.8.49 and below suffer from weak hashing, cross site request forgery, cross site scripting, and arbitrary file upload vulnerabilities.

tags | exploit, arbitrary, vulnerability, xss, file upload, csrf
advisories | CVE-2023-28153, CVE-2023-29078, CVE-2023-29079
SHA-256 | b33a2a364778cd72fba75e79c7bdf844aa87c6638b73e7e53fb94bf760948718
Monitorr 1.7.6m / 1.7.7d Remote Code Execution
Posted Mar 23, 2023
Authored by h00die-gr3y, Lyhins Lab | Site metasploit.com

This Metasploit module exploits an arbitrary file upload vulnerability and achieves remote code execution in the Monitorr application. Using a specially crafted request, custom PHP code can be uploaded and injected through endpoint upload.php because of missing input validation. Any user privileges can exploit this vulnerability and it results in access to the underlying operating system with the same privileges under which the web services run (typically user www-data). Monitorr versions 1.7.6m, 1.7.7d, and below are affected.

tags | exploit, remote, web, arbitrary, php, code execution, file upload
advisories | CVE-2020-28871
SHA-256 | 6c6d18b94bdb35bfe9807add78ec876cdeda11ffafe62ef4078fdeb348b08a51
Oracle E-Business Suite (EBS) Unauthenticated Arbitrary File Upload
Posted Mar 1, 2023
Authored by sf, HMs, l1k3beef | Site metasploit.com

This Metasploit module exploits an unauthenticated arbitrary file upload vulnerability in Oracle Web Applications Desktop Integrator, as shipped with Oracle EBS versions 12.2.3 through to 12.2.11, in order to gain remote code execution as the oracle user.

tags | exploit, remote, web, arbitrary, code execution, file upload
advisories | CVE-2022-21587
SHA-256 | a890c277f9518d69ee5b632d253b7c12b7da15367479577605ce796496a2f670
Ubuntu Security Notice USN-5868-1
Posted Feb 14, 2023
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 5868-1 - Jakob Ackermann discovered that Django incorrectly handled certain file uploads. A remote attacker could possibly use this issue to cause Django to consume resources, leading to a denial of service.

tags | advisory, remote, denial of service, file upload
systems | linux, ubuntu
advisories | CVE-2023-24580
SHA-256 | 11a790e108af509c2a344551f20a1e04c908295aa88e7d1ada09f38e4bf64cc5
Gold Filled CRM 2.0 Arbitrary File Upload
Posted Jan 12, 2023
Authored by indoushka

Gold Filled CRM version 2.0 suffers from an unauthenticated arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 7df5256a62f4b26f1e4415c585d3fa307a8092cdea4dec86c2b611cd1e38214d
ERPGo SaaS CRM 3.3 Arbitrary File Upload
Posted Jan 11, 2023
Authored by indoushka

ERPGo SaaS CRM version 3.3 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 75550497f441c15436243b166bf836846ad5f220742342f795cbab8cded44902
Roxy Fileman 1.4.6 Remote Shell Upload
Posted Nov 21, 2022
Authored by Hadi Mene

Roxy Fileman versions 1.4.6 and below remote shell upload proof of concept exploit.

tags | exploit, remote, shell, proof of concept, file upload
advisories | CVE-2022-40797
SHA-256 | 16a9c59173c82b869a340397a5e68377531e0e0f9be9781793142e4f47786e1b
WordPress Kaswara Modern WPBakery Page Builder 3.0.1 File Upload
Posted Jul 14, 2022
Site wordfence.com

WordPress Kaswara Modern WPBakery Page Builder plugin versions 3.0.1 and below suffer from an arbitrary file upload vulnerability.

tags | advisory, arbitrary, file upload
advisories | CVE-2021-24284
SHA-256 | cda2f52f6b43d9a253406aa83b3d7934624dc39c1c6c8f9a0240d741e6ae5fa3
PrestaShop 1.7.6.7 Cross Site Scripting
Posted Jul 14, 2022
Authored by Priyanka Samak

PrestaShop version 1.7.6.7 suffers from a cross site scripting vulnerability via the file upload functionality.

tags | exploit, xss, file upload
advisories | CVE-2020-21967
SHA-256 | fd8caaa9cec4a7055dd238f60bb28982f0acab62605c410f5808fff8eccaa174
Multi Language Pharmacy Management System 1.0 Shell Upload
Posted Jun 20, 2022
Authored by Emirhan Kurt | Site metasploit.com

This Metasploit module exploits the file upload vulnerability of Multi Language Pharmacy Management System to achieve remote code execution.

tags | exploit, remote, code execution, file upload
SHA-256 | 742456930e5e52c2ee76502248a99373d271bc23c86a2afc2380664719fcc4cb
e107 CMS 3.2.1 Arbitrary File Upload / Cross Site Scripting
Posted May 11, 2022
Authored by Hubert Wojciechowski

e107 CMS version 3.2.1 suffers from cross site scripting and arbitrary file upload vulnerabilities that can allow for a shell upload.

tags | exploit, arbitrary, shell, vulnerability, xss, file upload
SHA-256 | 3ae8caceae21f93d20493507ca607ad9781c300dc643e858c7c2ac8aa48b23b5
WordPress Advanced Uploader 4.2 Shell Upload
Posted May 11, 2022
Authored by Roel van Beurden

WordPress Advanced Uploader plugin versions 4.2 and below suffer from a remote shell upload vulnerability.

tags | exploit, remote, shell, file upload
advisories | CVE-2022-1103
SHA-256 | d6da47e9cfa89f863bdbab26f72fb5536450efbf87365b7899f665f69f1edd2a
ImpressCMS 1.4.4 Arbitrary File Upload
Posted May 11, 2022
Authored by Unsal Furkan Harani

ImpressCMS version 1.4.4 suffers from an arbitrary file upload due to a weak blacklisting methodology for file extensions.

tags | exploit, arbitrary, file upload
SHA-256 | e3a1d424f71f1feb571e0ac4b2912e399c1c124ebdfb5d9e83276acd5816f7e8
TLR-2005KSH Arbitrary File Upload
Posted May 11, 2022
Authored by Ahmed Alroky

TLR-2005KSH suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
advisories | CVE-2021-45428
SHA-256 | f7ccc88ff2a331dfcd6837d903e8a8b9647905703b086149bc856a1f4d52c2d9
WSO Arbitrary File Upload / Remote Code Execution
Posted May 2, 2022
Authored by Orange Tsai, wvu, hakivvi, Jack Heysel | Site metasploit.com

This Metasploit module abuses a vulnerability in certain WSO2 products that allow unrestricted file upload with resultant remote code execution. This affects WSO2 API Manager 2.2.0 and above through 4.0.0; WSO2 Identity Server 5.2.0 and above through 5.11.0; WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, and 5.6.0; WSO2 Identity Server as Key Manager 5.3.0 and above through 5.10.0; and WSO2 Enterprise Integrator 6.2.0 and above through 6.6.0.

tags | exploit, remote, code execution, file upload
advisories | CVE-2022-29464
SHA-256 | 7bdab9b3101da4ba2df8ff1f6a558171e4d8a503d4d44bcbaf0347587fa69a4d
Page 2 of 40
Back12345Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close