VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,339)

page 180 of 217
  • CVE-2022-4276MedDec 3, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown functionality of the file tenant-engine.php of the component POST Request Handler. The manipulation of the argument id_photo leads to unrestricted upload. The…

  • CVE-2022-4272MedDec 3, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown functionality of the file /product/savenewproduct.php?flag=1. The manipulation of the argument upfile leads to unrestricted upload. The attack may be launched…

  • CVE-2022-3944MedNov 11, 2022
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uploadImages of the file application/controllers/basedata/inventory.php of the component Commodity Management. The manipulation leads to unrestricted…

  • CVE-2022-39019MedOct 31, 2022
    risk 0.41cvss 6.3epss 0.00

    Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.

  • CVE-2022-3771MedOct 31, 2022
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of the file helpers/Upload.php of the component File Upload Management. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The…

  • CVE-2022-3458MedOct 12, 2022
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /employeeview.php of the component Image File Handler. The manipulation leads to unrestricted…

  • CVE-2022-3436MedOct 9, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file edit-photo.php of the component Photo Handler. The manipulation leads to unrestricted upload. The…

  • CVE-2022-3129MedSep 7, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in codeprojects Online Driving School. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registration.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has…

  • CVE-2022-2909MedAug 20, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation leads to unrestricted upload. The attack can be…

  • CVE-2022-2804MedAug 12, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Zoo Management System. It has been classified as critical. Affected is an unknown function of the file /pages/apply_vacancy.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the…

  • CVE-2022-2779MedAug 12, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in SourceCodester Gas Agency Management System. Affected by this vulnerability is an unknown functionality of the file /gasmark/assets/myimages/oneWord.php. The manipulation of the argument shell leads to unrestricted upload. The…

  • CVE-2022-2751MedAug 11, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/add-portfolio.php. The manipulation of the argument ufile leads to unrestricted upload. The attack may be…

  • CVE-2022-2750MedAug 11, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS. Affected is an unknown function of the file /dashboard/add-service.php of the component Add Service Handler. The manipulation leads to unrestricted upload. It is possible to…

  • CVE-2022-2746MedAug 11, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in SourceCodester Simple Online Book Store System and classified as critical. This vulnerability affects unknown code of the file Admin_ add.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-206014 is the…

  • CVE-2022-2744MedAug 11, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality of the file /admin/add_exercises.php of the component Background Management. The manipulation of the argument exer_img…

  • CVE-2022-2740MedAug 11, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability affects unknown code of the file /dashboard/add-blog.php of the component Add Blog. The manipulation of the argument ufile leads to unrestricted upload. The…

  • CVE-2022-2736MedAug 11, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unknown part of the file /dashboard/updatelogo.php of the component Background Upload Logo Icon. The manipulation of the argument xfile/ufile leads to…

  • CVE-2022-2694MedAug 6, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Company Website CMS and classified as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be…

  • CVE-2022-2678MedAug 5, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System. It has been declared as critical. This vulnerability affects unknown code of the file admin_feature.php of the component Background Management Page. The manipulation leads to unrestricted upload. The…

  • CVE-2022-2212MedJun 27, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Library Management System 1.0. It has been classified as critical. Affected is an unknown function of the component /card/index.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the…