VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 117 of 222
  • CVE-2022-39301HigOct 19, 2022
    risk 0.53cvss 8.2epss 0.00

    sra-admin is a background rights management system that separates the front and back end. sra-admin version 1.1.1 has a storage cross-site scripting (XSS) vulnerability. After logging into the sra-admin background, an attacker can upload an html page containing xss attack code…

  • CVE-2022-2419HigJul 15, 2022
    risk 0.53cvss 8.0epss 0.13

    A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code of the file _internal/collector/upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack to succeed.…

  • CVE-2021-27771HigMay 12, 2022
    risk 0.53cvss 8.2epss 0.01

    User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when…

  • CVE-2022-21809HigMay 12, 2022
    risk 0.53cvss 8.1epss 0.02

    A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.

  • CVE-2021-26628HigApr 26, 2022
    risk 0.53cvss 8.1epss 0.01

    Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a specific menu, the verification of the files is insufficient. It allows remote attackers to upload arbitrary files disguising them as…

  • CVE-2022-0403HigApr 4, 2022
    risk 0.53cvss 8.1epss 0.01

    The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any…

  • CVE-2022-26965HigMar 18, 2022
    risk 0.53cvss 7.2epss 0.36

    In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.

  • CVE-2021-27984HigDec 10, 2021
    risk 0.53cvss 8.1epss 0.03

    In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.

  • CVE-2021-42133HigDec 7, 2021
    risk 0.53cvss 8.1epss 0.03

    An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform an arbitrary file write.

  • CVE-2021-39608HigAug 23, 2021
    risk 0.53cvss 7.2epss 0.46

    Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code.

  • CVE-2021-20104HigJun 29, 2021
    risk 0.53cvss 8.1epss 0.02

    Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.

  • CVE-2020-25037HigFeb 2, 2021
    risk 0.53cvss 8.2epss 0.01

    UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted command.

  • CVE-2020-14008HigSep 4, 2020
    risk 0.53cvss 7.2epss 0.38

    Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.

  • CVE-2012-2950HigJan 9, 2020
    risk 0.53cvss 8.1epss 0.02

    Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information.

  • CVE-2019-12744HigJun 20, 2019
    risk 0.53cvss 7.5epss 0.12

    SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018-12940.

  • CVE-2017-3189HigJul 24, 2018
    risk 0.53cvss 8.1epss 0.07

    The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, there are no checks on the types of files…

  • CVE-2018-12528HigJul 2, 2018
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered on Intex N150 devices. The backup/restore option does not check the file extension uploaded for importing a configuration files backup, which can lead to corrupting the router firmware settings or even the uploading of malicious files. In order to exploit…

  • CVE-2018-1000094HigMar 13, 2018
    risk 0.53cvss 7.2epss 0.39

    CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. This attack appear to be exploitable via File upload -> copy to any…

  • CVE-2026-50006CriSep 14, 2026
    risk 0.52cvss 9.1epss 0.01

    Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacker can select any path writable by the…

  • CVE-2026-49849CriAug 21, 2026
    risk 0.52cvss 9.1epss 0.01

    xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially crafted php file, an attacker can achieve Remote Code…