VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,444)

page 123 of 223
  • CVE-2024-23762HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload of crafted PHP file.

  • CVE-2023-25365HigFeb 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

  • CVE-2023-41725HigNov 3, 2023
    risk 0.51cvss 7.8epss 0.01

    Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability

  • CVE-2023-45555HigOct 25, 2023
    risk 0.51cvss 7.8epss 0.01

    File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php file.

  • CVE-2023-44824HigOct 17, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component.

  • CVE-2023-43838HigOct 4, 2023
    risk 0.51cvss 7.8epss 0.01

    An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.

  • CVE-2023-41902HigSep 20, 2023
    risk 0.51cvss 7.8epss 0.00

    An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to escalate privileges by crafting malicious .pkg files.

  • CVE-2023-34394HigJul 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service…

  • CVE-2023-37208HigJul 5, 2023
    risk 0.51cvss 7.8epss 0.00

    When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.

  • CVE-2021-27280HigMay 8, 2023
    risk 0.51cvss 7.8epss 0.01

    OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.

  • CVE-2022-45415HigDec 22, 2022
    risk 0.51cvss 7.8epss 0.00

    When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox <…

  • CVE-2022-0517HigDec 22, 2022
    risk 0.51cvss 7.8epss 0.00

    Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to launch arbitrary code with SYSTEM privilege. This vulnerability affects Mozilla VPN < 2.7.1.

  • CVE-2022-45338HigDec 15, 2022
    risk 0.51cvss 7.8epss 0.00

    An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterprise 500 before 500SP6 allows attackers to execute arbitrary code via a crafted SVG file.

  • CVE-2022-29637HigMay 26, 2022
    risk 0.51cvss 7.8epss 0.01

    An arbitrary file upload vulnerability in Mindoc v2.1-beta.5 allows attackers to execute arbitrary commands via a crafted Zip file.

  • CVE-2022-22392HigApr 25, 2022
    risk 0.51cvss 7.8epss 0.02

    IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066.

  • CVE-2020-26008HigMar 20, 2022
    risk 0.51cvss 7.8epss 0.01

    The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2020-26007HigMar 20, 2022
    risk 0.51cvss 7.8epss 0.01

    An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2022-25581HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.

  • CVE-2022-26521HigMar 10, 2022
    risk 0.51cvss 7.2epss 0.10

    Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can be changed by an administrator (e.g., by configuring .php to be a valid image file type).

  • CVE-2022-25115HigMar 2, 2022
    risk 0.51cvss 7.8epss 0.02

    A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners Collection Management System v1.0 allows attackers to execute arbitrary code via a crafted PNG file.