CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,316)
page 101 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32243 | Hig | 0.57 | 8.8 | 0.01 | Jun 16, 2021 | FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated). | ||
| CVE-2021-27489 | Hig | 0.57 | 8.8 | 0.01 | Jun 16, 2021 | ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file could allow an attacker to remotely execute arbitrary commands. | ||
| CVE-2021-34128 | Hig | 0.57 | 8.8 | 0.01 | Jun 15, 2021 | LaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=pay to upload a ZIP archive containing a .php file, as demonstrated by the ../../../../phpinfo.php pathname. | ||
| CVE-2020-36141 | Hig | 0.57 | 8.8 | 0.01 | Jun 4, 2021 | BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header. | ||
| CVE-2021-29092 | Hig | 0.57 | 8.8 | 0.02 | Jun 1, 2021 | Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified vectors. | ||
| CVE-2021-24311 | Hig | 0.57 | 8.8 | 0.02 | Jun 1, 2021 | The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users. | ||
| CVE-2020-26678 | Hig | 0.57 | 8.8 | 0.02 | May 26, 2021 | vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execution. | ||
| CVE-2021-32094 | Hig | 0.57 | 8.8 | 0.01 | May 7, 2021 | U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to upload arbitrary files. | ||
| CVE-2021-24253 | Hig | 0.57 | 8.8 | 0.02 | May 6, 2021 | The Classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds a listing, only checking the content-type in the request. This allows any authenticated user to upload arbitrary PHP files via the Add Listing feature of the… | ||
| CVE-2021-24224 | Hig | 0.57 | 8.8 | 0.02 | Apr 12, 2021 | The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any security in place to verify uploaded files, allowing low privilege users to upload arbitrary files, leading to RCE. | ||
| CVE-2021-24155 | Hig | 0.57 | 7.2 | 0.84 | Apr 5, 2021 | The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE. | ||
| CVE-2021-20659 | Hig | 0.57 | 8.8 | 0.02 | Feb 24, 2021 | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code. | ||
| CVE-2021-22858 | Hig | 0.57 | 8.8 | 0.01 | Feb 17, 2021 | Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions. | ||
| CVE-2020-24549 | Hig | 0.57 | 8.8 | 0.03 | Jan 26, 2021 | openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server. | ||
| CVE-2020-35627 | Hig | 0.57 | 8.8 | 0.02 | Dec 28, 2020 | Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code. Once it contains the function "Custom Gift Card Template", the function of uploading a custom image is used, changing the… | ||
| CVE-2020-27397 | Hig | 0.57 | 8.8 | 0.03 | Dec 23, 2020 | Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain remote code execution (RCE) on the Hosting web server via uploading a maliciously crafted PHP file. | ||
| CVE-2020-26174 | Hig | 0.57 | 8.8 | 0.01 | Dec 18, 2020 | tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this list. However, this restriction is enforced in the browser (client-side) and can be circumvented. This allows an attacker to… | ||
| CVE-2020-7569 | Hig | 0.57 | 8.8 | 0.02 | Nov 19, 2020 | A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to upload arbitrary files due to incorrect verification of user supplied files and… | ||
| CVE-2020-28136 | Hig | 0.57 | 8.8 | 0.03 | Nov 17, 2020 | An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page. | ||
| CVE-2020-28693 | Hig | 0.57 | 8.8 | 0.03 | Nov 16, 2020 | An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PHP file via an HTTP GET request to /themes/<php_file_name> |
- risk 0.57cvss 8.8epss 0.01
FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).
- risk 0.57cvss 8.8epss 0.01
ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file could allow an attacker to remotely execute arbitrary commands.
- risk 0.57cvss 8.8epss 0.01
LaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=pay to upload a ZIP archive containing a .php file, as demonstrated by the ../../../../phpinfo.php pathname.
- risk 0.57cvss 8.8epss 0.01
BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.
- risk 0.57cvss 8.8epss 0.02
Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified vectors.
- risk 0.57cvss 8.8epss 0.02
The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users.
- risk 0.57cvss 8.8epss 0.02
vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execution.
- risk 0.57cvss 8.8epss 0.01
U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to upload arbitrary files.
- risk 0.57cvss 8.8epss 0.02
The Classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds a listing, only checking the content-type in the request. This allows any authenticated user to upload arbitrary PHP files via the Add Listing feature of the…
- risk 0.57cvss 8.8epss 0.02
The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any security in place to verify uploaded files, allowing low privilege users to upload arbitrary files, leading to RCE.
- risk 0.57cvss 7.2epss 0.84
The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.
- risk 0.57cvss 8.8epss 0.02
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code.
- risk 0.57cvss 8.8epss 0.01
Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions.
- risk 0.57cvss 8.8epss 0.03
openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server.
- risk 0.57cvss 8.8epss 0.02
Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code. Once it contains the function "Custom Gift Card Template", the function of uploading a custom image is used, changing the…
- risk 0.57cvss 8.8epss 0.03
Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain remote code execution (RCE) on the Hosting web server via uploading a maliciously crafted PHP file.
- risk 0.57cvss 8.8epss 0.01
tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this list. However, this restriction is enforced in the browser (client-side) and can be circumvented. This allows an attacker to…
- risk 0.57cvss 8.8epss 0.02
A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to upload arbitrary files due to incorrect verification of user supplied files and…
- risk 0.57cvss 8.8epss 0.03
An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.
- risk 0.57cvss 8.8epss 0.03
An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PHP file via an HTTP GET request to /themes/<php_file_name>