CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,316)
page 145 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-26607 | Hig | 0.47 | 7.2 | 0.02 | Apr 6, 2022 | A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2020-28062 | Hig | 0.47 | 7.2 | 0.02 | Apr 4, 2022 | An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote malicious user execute arbitrary code. | ||
| CVE-2022-0537 | Hig | 0.47 | 7.2 | 0.01 | Apr 4, 2022 | The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the current 's stylesheet… | ||
| CVE-2022-23155 | Hig | 0.47 | 7.2 | 0.01 | Apr 1, 2022 | Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can exploit this vulnerability in order to execute arbitrary code on the system. | ||
| CVE-2021-43103 | Hig | 0.47 | 7.2 | 0.02 | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. | ||
| CVE-2021-43102 | Hig | 0.47 | 7.2 | 0.02 | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. | ||
| CVE-2021-43101 | Hig | 0.47 | 7.2 | 0.02 | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. | ||
| CVE-2021-43100 | Hig | 0.47 | 7.2 | 0.02 | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. | ||
| CVE-2021-43098 | Hig | 0.47 | 7.2 | 0.01 | Mar 28, 2022 | A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function. | ||
| CVE-2022-0440 | Hig | 0.47 | 7.2 | 0.01 | Mar 7, 2022 | The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML,… | ||
| CVE-2022-23906 | Hig | 0.47 | 7.2 | 0.02 | Feb 28, 2022 | CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file. | ||
| CVE-2022-23048 | Hig | 0.47 | 7.2 | 0.02 | Feb 9, 2022 | Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where can be accessed in order to execute… | ||
| CVE-2021-44255 | Hig | 0.47 | 7.2 | 0.03 | Jan 31, 2022 | Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrary code on the server. | ||
| CVE-2021-46116 | Hig | 0.47 | 7.2 | 0.02 | Jan 26, 2022 | jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code. | ||
| CVE-2021-46115 | Hig | 0.47 | 7.2 | 0.01 | Jan 26, 2022 | jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code. | ||
| CVE-2021-41550 | Hig | 0.47 | 7.2 | 0.01 | Jan 18, 2022 | Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code. | ||
| CVE-2021-46079 | Hig | 0.47 | 7.2 | 0.03 | Jan 6, 2022 | An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to Html Injection. | ||
| CVE-2021-22968 | Hig | 0.47 | 7.2 | 0.03 | Nov 19, 2021 | A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versions 8.5.6 and below.The external file upload feature stages files in the public directory even if they have disallowed file… | ||
| CVE-2021-41675 | Hig | 0.47 | 7.2 | 0.03 | Oct 29, 2021 | A Remote Code Execution (RCE) vulnerabilty exists in Sourcecodester E-Negosyo System 1.0 in /admin/produts/controller.php via the doInsert function, which validates images with getImageSizei. . | ||
| CVE-2021-40189 | Hig | 0.47 | 7.2 | 0.02 | Oct 11, 2021 | PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an attacker can access and execute arbitrary code. |
- risk 0.47cvss 7.2epss 0.02
A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.47cvss 7.2epss 0.02
An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote malicious user execute arbitrary code.
- risk 0.47cvss 7.2epss 0.01
The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the current 's stylesheet…
- risk 0.47cvss 7.2epss 0.01
Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can exploit this vulnerability in order to execute arbitrary code on the system.
- risk 0.47cvss 7.2epss 0.02
A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.
- risk 0.47cvss 7.2epss 0.02
A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.
- risk 0.47cvss 7.2epss 0.02
A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.
- risk 0.47cvss 7.2epss 0.02
A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.
- risk 0.47cvss 7.2epss 0.01
A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function.
- risk 0.47cvss 7.2epss 0.01
The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML,…
- risk 0.47cvss 7.2epss 0.02
CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.
- risk 0.47cvss 7.2epss 0.02
Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where can be accessed in order to execute…
- risk 0.47cvss 7.2epss 0.03
Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrary code on the server.
- risk 0.47cvss 7.2epss 0.02
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code.
- risk 0.47cvss 7.2epss 0.01
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code.
- risk 0.47cvss 7.2epss 0.01
Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
- risk 0.47cvss 7.2epss 0.03
An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to Html Injection.
- risk 0.47cvss 7.2epss 0.03
A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versions 8.5.6 and below.The external file upload feature stages files in the public directory even if they have disallowed file…
- risk 0.47cvss 7.2epss 0.03
A Remote Code Execution (RCE) vulnerabilty exists in Sourcecodester E-Negosyo System 1.0 in /admin/produts/controller.php via the doInsert function, which validates images with getImageSizei. .
- risk 0.47cvss 7.2epss 0.02
PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an attacker can access and execute arbitrary code.