CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,316)
page 140 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-47129 | Hig | 0.47 | 8.3 | 0.01 | Nov 10, 2023 | Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_… | ||
| CVE-2023-46004 | Hig | 0.47 | 7.2 | 0.01 | Oct 18, 2023 | Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function. | ||
| CVE-2022-22375 | Hig | 0.47 | 7.2 | 0.01 | Oct 17, 2023 | IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 221681. | ||
| CVE-2023-4817 | Hig | 0.47 | 7.2 | 0.01 | Oct 3, 2023 | This vulnerability allows an authenticated attacker to upload malicious files by bypassing the restrictions of the upload functionality, compromising the entire device. | ||
| CVE-2023-40219 | Hig | 0.47 | 7.2 | 0.01 | Sep 27, 2023 | Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory. | ||
| CVE-2023-39377 | Hig | 0.47 | 7.2 | 0.01 | Sep 27, 2023 | SiberianCMS - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method | ||
| CVE-2023-3375 | Hig | 0.47 | 7.2 | 0.01 | Sep 5, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in Unisign Bookreen allows OS Command Injection. This issue affects Bookreen: before 3.0.0. | ||
| CVE-2023-40825 | Hig | 0.47 | 7.2 | 0.01 | Aug 28, 2023 | An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list. | ||
| CVE-2023-31946 | Hig | 0.47 | 7.2 | 0.01 | Aug 17, 2023 | File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php. | ||
| CVE-2023-31941 | Hig | 0.47 | 7.2 | 0.01 | Aug 17, 2023 | File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the employee_insert.php. | ||
| CVE-2020-23564 | Hig | 0.47 | 7.2 | 0.01 | Aug 5, 2023 | File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php. | ||
| CVE-2023-38947 | Hig | 0.47 | 7.2 | 0.01 | Aug 3, 2023 | An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2023-3836 | Med | 0.47 | 6.3 | 0.74 | Jul 22, 2023 | A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricted upload. The attack can… | ||
| CVE-2023-38404 | Hig | 0.47 | 7.2 | 0.01 | Jul 17, 2023 | The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server. | ||
| CVE-2023-32621 | Hig | 0.47 | 7.2 | 0.01 | Jun 30, 2023 | WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to upload arbitrary files and execute OS commands with the root privilege. | ||
| CVE-2023-34736 | Hig | 0.47 | 7.2 | 0.01 | Jun 28, 2023 | Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload. | ||
| CVE-2023-27083 | Hig | 0.47 | 7.2 | 0.01 | Jun 22, 2023 | An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality. | ||
| CVE-2020-20919 | Hig | 0.47 | 7.2 | 0.01 | Jun 20, 2023 | File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file. | ||
| CVE-2022-33166 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2023 | IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 228586. | ||
| CVE-2023-33569 | Hig | 0.47 | 7.2 | 0.01 | Jun 6, 2023 | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user. |
- risk 0.47cvss 8.3epss 0.01
Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_…
- risk 0.47cvss 7.2epss 0.01
Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function.
- risk 0.47cvss 7.2epss 0.01
IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 221681.
- risk 0.47cvss 7.2epss 0.01
This vulnerability allows an authenticated attacker to upload malicious files by bypassing the restrictions of the upload functionality, compromising the entire device.
- risk 0.47cvss 7.2epss 0.01
Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory.
- risk 0.47cvss 7.2epss 0.01
SiberianCMS - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method
- risk 0.47cvss 7.2epss 0.01
Unrestricted Upload of File with Dangerous Type vulnerability in Unisign Bookreen allows OS Command Injection. This issue affects Bookreen: before 3.0.0.
- risk 0.47cvss 7.2epss 0.01
An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list.
- risk 0.47cvss 7.2epss 0.01
File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php.
- risk 0.47cvss 7.2epss 0.01
File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the employee_insert.php.
- risk 0.47cvss 7.2epss 0.01
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
- risk 0.47cvss 7.2epss 0.01
An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 6.3epss 0.74
A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricted upload. The attack can…
- risk 0.47cvss 7.2epss 0.01
The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.
- risk 0.47cvss 7.2epss 0.01
WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to upload arbitrary files and execute OS commands with the root privilege.
- risk 0.47cvss 7.2epss 0.01
Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload.
- risk 0.47cvss 7.2epss 0.01
An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.
- risk 0.47cvss 7.2epss 0.01
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.
- risk 0.47cvss 7.2epss 0.01
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 228586.
- risk 0.47cvss 7.2epss 0.01
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user.