VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 142 of 216
  • CVE-2022-45427HigDec 27, 2022
    risk 0.47cvss 7.2epss 0.01

    Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can upload arbitrary files.

  • CVE-2022-46135HigDec 16, 2022
    risk 0.47cvss 7.2epss 0.01

    In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and control the web server.

  • CVE-2022-45009HigDec 7, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-45912HigDec 5, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admin user. An authenticated admin user can upload files through the ClientUploader utility, and traverse to any other directory for…

  • CVE-2022-45039HigNov 25, 2022
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-30529HigNov 22, 2022
    risk 0.47cvss 7.2epss 0.01

    File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to upload arbitrary files via /system/application/libs/js/tinymce/plugins/filemanager/dialog.php and /system/application/libs/js/tinymce/plugins/filemanager/up…

  • CVE-2022-43146HigNov 14, 2022
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-43277HigNov 9, 2022
    risk 0.47cvss 7.2epss 0.01

    Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via ip/youthappam/php_action/editFile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-43050HigNov 7, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component update_profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-43061HigNov 3, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/travellers.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-43085HigNov 1, 2022
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-43083HigNov 1, 2022
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in admin-add-vehicle.php of Vehicle Booking System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-43231HigOct 28, 2022
    risk 0.47cvss 7.2epss 0.01

    Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_website.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-43275HigOct 28, 2022
    risk 0.47cvss 7.2epss 0.01

    Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-39978HigOct 27, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the Product List module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.

  • CVE-2022-39977HigOct 27, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the User module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.

  • CVE-2022-42189HigOct 21, 2022
    risk 0.47cvss 7.2epss 0.02

    Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.

  • CVE-2022-42201HigOct 20, 2022
    risk 0.47cvss 7.2epss 0.01

    Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.

  • CVE-2022-31366HigOct 20, 2022
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file.

  • CVE-2022-41537HigOct 18, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /user_operations/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.