VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,339)

page 199 of 217
  • CVE-2023-5812MedOct 27, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability has been found in flusity CMS and classified as critical. Affected by this vulnerability is the function handleFileUpload of the file core/tools/upload.php. The manipulation of the argument uploaded_file leads to unrestricted upload. The attack can be launched…

  • CVE-2023-41626MedSep 15, 2023
    risk 0.31cvss 4.8epss 0.00

    Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the /upload interface.

  • CVE-2023-2888MedMay 25, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&_noCache=0.1683794968. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The…

  • CVE-2023-2419MedApr 29, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the file \crmeb\app\services\system\attachment\SystemAttachmentServices.php. The manipulation of the argument filename leads to…

  • CVE-2023-1684MedMar 29, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in HadSky 7.7.16. It has been classified as problematic. This affects an unknown part of the file upload/index.php?c=app&a=superadmin:index. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has…

  • CVE-2023-1559MedMar 22, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as problematic was found in SourceCodester Storage Unit Rental Management System 1.0. This vulnerability affects unknown code of the file classes/Users.php?f=save. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The…

  • CVE-2023-1442MedMar 17, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in Meizhou Qingyunke QYKCMS 4.3.0. It has been classified as problematic. This affects an unknown part of the file /admin_system/api.php of the component Update Handler. The manipulation of the argument downurl leads to unrestricted upload. It is…

  • CVE-2023-1433MedMar 16, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Gadget Works Online Ordering System 1.0. It has been classified as problematic. This affects an unknown part of the file admin/products/controller.php?action=add of the component Products Handler. The manipulation of the argument…

  • CVE-2023-1391MedMar 14, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/ab.php. The manipulation of the argument img leads to unrestricted upload. It is possible to launch…

  • CVE-2023-1328MedMar 10, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in Guizhou 115cms 4.2. It has been classified as problematic. Affected is an unknown function of the file /admin/content/index. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2023-27164MedMar 10, 2023
    risk 0.31cvss 4.8epss 0.01

    An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.

  • CVE-2023-1185MedMar 6, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of the component New Product Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed…

  • CVE-2023-1184MedMar 6, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is some unknown functionality of the file admin/database.php of the component Backup Database Handler. The manipulation leads to unrestricted upload. The attack may…

  • CVE-2023-0783MedFeb 11, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in EcShop 4.1.5. It has been classified as critical. This affects an unknown part of the file /ecshop/admin/template.php of the component PHP File Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely.…

  • CVE-2023-0257MedJan 12, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /fos/admin/index.php?page=menu of the component Menu Form. The manipulation of the argument Image…

  • CVE-2022-4232MedNov 30, 2022
    risk 0.31cvss 4.7epss 0.00

    A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected is an unknown function. The manipulation of the argument cmd leads to unrestricted upload. It is possible to launch the attack remotely. VDB-214590 is the…

  • CVE-2022-3549MedOct 17, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /csms/admin/?page=user/manage_user of the component Avatar Handler. The manipulation leads to…

  • CVE-2022-2749MedAug 11, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Gym Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mygym/admin/index.php?view_exercises. The manipulation leads to unrestricted upload. The attack can be…

  • CVE-2021-41421MedJun 16, 2022
    risk 0.31cvss 4.8epss 0.00

    A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel.

  • CVE-2022-1837MedMay 24, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this issue is register.php?link=registerand. The manipulation with the input <?php phpinfo();?> leads to code execution. The attack may be launched remotely but…