Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the “save_animal” file of the “Animals” module in the background management system.
CWE-434
CVE-2022-40925
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the “save_event” file of the “Events” module in the background management system.
CVE-2022-40932
In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the “gallery” file of the “Gallery” module in the background management system.
CVE-2022-40981
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of this to store malicious files on the server, which could override sensitive and useful existing files on the filesystem, fill the hard disk to full capacity, or compromise the affected device or computers with administrator level privileges connected to the affected device.
CVE-2022-40878
In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).
CVE-2022-40886
DedeCMS 5.7.98 has a file upload vulnerability in the background.