CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,434)
page 121 of 222| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45136 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious file which can then be… | ||
| CVE-2024-44871 | Hig | 0.51 | 7.2 | 0.16 | Sep 10, 2024 | An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2024-7987 | Hig | 0.51 | 7.8 | 0.00 | Aug 26, 2024 | A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a… | ||
| CVE-2024-3483 | Hig | 0.51 | 7.8 | 0.01 | May 15, 2024 | Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues. | ||
| CVE-2024-23762 | Hig | 0.51 | 7.8 | 0.00 | Feb 12, 2024 | Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload of crafted PHP file. | ||
| CVE-2023-25365 | Hig | 0.51 | 7.8 | 0.00 | Feb 8, 2024 | Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3 | ||
| CVE-2023-41725 | Hig | 0.51 | 7.8 | 0.01 | Nov 3, 2023 | Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability | ||
| CVE-2023-45555 | Hig | 0.51 | 7.8 | 0.01 | Oct 25, 2023 | File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php file. | ||
| CVE-2023-44824 | Hig | 0.51 | 7.8 | 0.00 | Oct 17, 2023 | An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component. | ||
| CVE-2023-43838 | Hig | 0.51 | 7.8 | 0.01 | Oct 4, 2023 | An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar. | ||
| CVE-2023-41902 | Hig | 0.51 | 7.8 | 0.00 | Sep 20, 2023 | An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to escalate privileges by crafting malicious .pkg files. | ||
| CVE-2023-34394 | Hig | 0.51 | 7.8 | 0.00 | Jul 19, 2023 | In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service… | ||
| CVE-2023-37208 | Hig | 0.51 | 7.8 | 0.00 | Jul 5, 2023 | When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13. | ||
| CVE-2021-27280 | Hig | 0.51 | 7.8 | 0.01 | May 8, 2023 | OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected. | ||
| CVE-2022-45415 | Hig | 0.51 | 7.8 | 0.00 | Dec 22, 2022 | When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox <… | ||
| CVE-2022-0517 | Hig | 0.51 | 7.8 | 0.00 | Dec 22, 2022 | Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to launch arbitrary code with SYSTEM privilege. This vulnerability affects Mozilla VPN < 2.7.1. | ||
| CVE-2022-45338 | Hig | 0.51 | 7.8 | 0.00 | Dec 15, 2022 | An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterprise 500 before 500SP6 allows attackers to execute arbitrary code via a crafted SVG file. | ||
| CVE-2022-29637 | Hig | 0.51 | 7.8 | 0.01 | May 26, 2022 | An arbitrary file upload vulnerability in Mindoc v2.1-beta.5 allows attackers to execute arbitrary commands via a crafted Zip file. | ||
| CVE-2022-22392 | Hig | 0.51 | 7.8 | 0.02 | Apr 25, 2022 | IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066. | ||
| CVE-2020-26008 | Hig | 0.51 | 7.8 | 0.01 | Mar 20, 2022 | The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via uploading a crafted PHP file. |
- risk 0.51cvss 7.8epss 0.00
InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious file which can then be…
- risk 0.51cvss 7.2epss 0.16
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.51cvss 7.8epss 0.00
A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a…
- risk 0.51cvss 7.8epss 0.01
Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.
- risk 0.51cvss 7.8epss 0.00
Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload of crafted PHP file.
- risk 0.51cvss 7.8epss 0.00
Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3
- risk 0.51cvss 7.8epss 0.01
Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability
- risk 0.51cvss 7.8epss 0.01
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php file.
- risk 0.51cvss 7.8epss 0.00
An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component.
- risk 0.51cvss 7.8epss 0.01
An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.
- risk 0.51cvss 7.8epss 0.00
An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to escalate privileges by crafting malicious .pkg files.
- risk 0.51cvss 7.8epss 0.00
In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service…
- risk 0.51cvss 7.8epss 0.00
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
- risk 0.51cvss 7.8epss 0.01
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.
- risk 0.51cvss 7.8epss 0.00
When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox <…
- risk 0.51cvss 7.8epss 0.00
Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to launch arbitrary code with SYSTEM privilege. This vulnerability affects Mozilla VPN < 2.7.1.
- risk 0.51cvss 7.8epss 0.00
An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterprise 500 before 500SP6 allows attackers to execute arbitrary code via a crafted SVG file.
- risk 0.51cvss 7.8epss 0.01
An arbitrary file upload vulnerability in Mindoc v2.1-beta.5 allows attackers to execute arbitrary commands via a crafted Zip file.
- risk 0.51cvss 7.8epss 0.02
IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066.
- risk 0.51cvss 7.8epss 0.01
The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via uploading a crafted PHP file.