VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,451)

page 165 of 223
  • CVE-2024-29368MedApr 22, 2024
    risk 0.42cvss 6.5epss 0.01

    An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file execution or storage of malicious content.

  • CVE-2024-31210HigApr 4, 2024
    risk 0.42cvss 7.6epss 0.01

    WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for…

  • CVE-2024-28520MedApr 4, 2024
    risk 0.42cvss 6.5epss 0.00

    File Upload vulnerability in Byzoro Networks Smart multi-service security gateway intelligent management platform version S210, allows an attacker to obtain sensitive information via the uploadfile.php component.

  • CVE-2024-28418MedMar 14, 2024
    risk 0.42cvss 6.5epss 0.00

    Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php

  • CVE-2024-24146MedFeb 29, 2024
    risk 0.42cvss 6.5epss 0.01

    A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.

  • CVE-2022-45377MedDec 21, 2023
    risk 0.42cvss 6.5epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8.

  • CVE-2023-6827HigDec 15, 2023
    risk 0.42cvss 7.5epss 0.01

    The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFonts' function in versions up to, and including, 4.3.5. This makes it possible for authenticated attackers with subscriber-level…

  • CVE-2023-5154MedSep 25, 2023
    risk 0.42cvss 6.3epss 0.15

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-8000 up to 20151231 and classified as critical. This vulnerability affects unknown code of the file /sysmanage/changelogo.php. The manipulation of the argument file_upload leads to unrestricted upload.…

  • CVE-2023-24517MedAug 22, 2023
    risk 0.42cvss 6.4epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands. This issue affects Pandora FMS v767 version and prior…

  • CVE-2023-28482MedAug 14, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different users. The TigerGraph platform does not protect the confidentiality of any data uploaded to the remote server. In this scenario,…

  • CVE-2023-28480MedAug 14, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform allows users to define new User Defined Functions (UDFs) from C/C++ code. To support this functionality TigerGraph allows users to upload custom C/C++ code which is then compiled and installed into…

  • CVE-2023-32526MedJun 26, 2023
    risk 0.42cvss 6.5epss 0.02

    Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2023-32525MedJun 26, 2023
    risk 0.42cvss 6.5epss 0.02

    Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2023-34660MedJun 16, 2023
    risk 0.42cvss 6.5epss 0.01

    jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.

  • CVE-2023-22504MedMay 25, 2023
    risk 0.42cvss 6.5epss 0.01

    Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.

  • CVE-2023-20073MedApr 5, 2023
    risk 0.42cvss 5.3epss 0.90

    A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insufficient authorization…

  • CVE-2023-28652MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.01

    An authenticated malicious user could successfully upload a malicious image could lead to a denial-of-service condition.

  • CVE-2023-20009MedMar 1, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The…

  • CVE-2023-24045MedMar 1, 2023
    risk 0.42cvss 6.5epss 0.01

    In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.

  • CVE-2022-40217MedSep 21, 2022
    risk 0.42cvss 6.5epss 0.01

    Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.