VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 140 of 216
  • CVE-2023-47129HigNov 10, 2023
    risk 0.47cvss 8.3epss 0.01

    Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_…

  • CVE-2023-46004HigOct 18, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function.

  • CVE-2022-22375HigOct 17, 2023
    risk 0.47cvss 7.2epss 0.01

    IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 221681.

  • CVE-2023-4817HigOct 3, 2023
    risk 0.47cvss 7.2epss 0.01

    This vulnerability allows an authenticated attacker to upload malicious files by bypassing the restrictions of the upload functionality, compromising the entire device.

  • CVE-2023-40219HigSep 27, 2023
    risk 0.47cvss 7.2epss 0.01

    Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory.

  • CVE-2023-39377HigSep 27, 2023
    risk 0.47cvss 7.2epss 0.01

    SiberianCMS - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method

  • CVE-2023-3375HigSep 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Unisign Bookreen allows OS Command Injection. This issue affects Bookreen: before 3.0.0.

  • CVE-2023-40825HigAug 28, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list.

  • CVE-2023-31946HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.01

    File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php.

  • CVE-2023-31941HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.01

    File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the employee_insert.php.

  • CVE-2020-23564HigAug 5, 2023
    risk 0.47cvss 7.2epss 0.01

    File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.

  • CVE-2023-38947HigAug 3, 2023
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2023-3836MedJul 22, 2023
    risk 0.47cvss 6.3epss 0.74

    A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricted upload. The attack can…

  • CVE-2023-38404HigJul 17, 2023
    risk 0.47cvss 7.2epss 0.01

    The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.

  • CVE-2023-32621HigJun 30, 2023
    risk 0.47cvss 7.2epss 0.01

    WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to upload arbitrary files and execute OS commands with the root privilege.

  • CVE-2023-34736HigJun 28, 2023
    risk 0.47cvss 7.2epss 0.01

    Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload.

  • CVE-2023-27083HigJun 22, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.

  • CVE-2020-20919HigJun 20, 2023
    risk 0.47cvss 7.2epss 0.01

    File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.

  • CVE-2022-33166HigJun 15, 2023
    risk 0.47cvss 7.2epss 0.01

    IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 228586.

  • CVE-2023-33569HigJun 6, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user.