• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-434

CVE-2019-9623

February 26, 2023 by

Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via “<!–#exec cmd=" in a .shtml file to ck_upload_handler.php.

CVE-2019-9572

February 26, 2023 by

SchoolCMS version 2.3.1 allows file upload via the theme upload feature at admin.php?m=admin&c=theme&a=upload by using the .zip extension along with the _Static substring, changing the Content-Type to application/zip, and placing PHP code after the ZIP header. This ultimately allows execution of arbitrary PHP code in PublicHome1_Static.php because of mishandling in the ApplicationAdminControllerThemeController.class.php Upload() function.

CVE-2019-9581

February 26, 2023 by

phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresenter.php does not ensure an image file extension.

CVE-2019-9181

February 26, 2023 by

SchoolCMS version 2.3.1 allows file upload via the logo upload feature at admin.php?m=admin&c=site&a=save by using the .jpg extension, changing the Content-Type to image/php, and placing PHP code after the JPEG data. This ultimately allows execution of arbitrary PHP code.

CVE-2019-9185

February 26, 2023 by

Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension.

CVE-2019-9189

February 26, 2023 by

Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately executed because of root code execution, not as a web server user, allowing an authenticated attacker to gain full system access.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 73
  • Go to page 74
  • Go to page 75
  • Go to page 76
  • Go to page 77
  • Interim pages omitted …
  • Go to page 224
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE