VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 16 of 222
  • CVE-2022-45359CriDec 6, 2022
    risk 0.65cvss 9.8epss 0.14

    Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.

  • CVE-2021-38397CriOct 28, 2022
    risk 0.65cvss 10.0epss 0.01

    Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.

  • CVE-2020-8974CriOct 17, 2022
    risk 0.65cvss 10.0epss 0.01

    In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type of restriction. This allows an attacker to modify it and re-upload it via web with malicious modifications, rendering the device unusable.

  • CVE-2022-38916CriSep 20, 2022
    risk 0.65cvss 9.8epss 0.18

    A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files

  • CVE-2022-1952CriJul 11, 2022
    risk 0.65cvss 9.8epss 0.25

    The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected…

  • CVE-2022-32994CriJun 27, 2022
    risk 0.65cvss 9.8epss 0.19

    Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.

  • CVE-2022-1519CriJun 24, 2022
    risk 0.65cvss 10.0epss 0.01

    LRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any file type, including executable code that allows for a remote code exploit.

  • CVE-2022-30808CriJun 2, 2022
    risk 0.65cvss 9.8epss 0.17

    elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php.

  • CVE-2022-29632CriMay 26, 2022
    risk 0.65cvss 9.8epss 0.17

    An arbitrary file upload vulnerability in the component /course/api/upload/pic of Roncoo Education v9.0.0 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2021-42645CriMay 10, 2022
    risk 0.65cvss 10.0epss 0.05

    CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable host.

  • CVE-2022-23329CriFeb 4, 2022
    risk 0.65cvss 9.8epss 0.14

    A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.

  • CVE-2021-42840HigOct 22, 2021
    risk 0.65cvss 8.8epss 0.59

    SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP…

  • CVE-2021-37924CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37923CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37921CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37920CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37919CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-27198CriFeb 26, 2021
    risk 0.65cvss 9.8epss 0.14

    An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI. This application is written in Java and is thus cross-platform. The…

  • CVE-2020-35949CriJan 1, 2021
    risk 0.65cvss 10.0epss 0.05

    An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type…

  • CVE-2020-35945CriJan 1, 2021
    risk 0.65cvss 9.9epss 0.02

    An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file…