VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,297)

page 2 of 215
  • CVE-2020-12800CriJun 8, 2020
    risk 0.73cvss 9.8epss 0.79

    The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.

  • CVE-2013-0803CriFeb 11, 2020
    risk 0.73cvss 9.8epss 0.75

    A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.

  • CVE-2013-7390CriJan 27, 2020
    risk 0.73cvss 9.8epss 0.75

    Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the…

  • CVE-2014-8516CriJan 3, 2020
    risk 0.73cvss 9.8epss 0.82

    Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.

  • CVE-2018-20526CriMar 21, 2019
    risk 0.73cvss 9.8epss 0.73

    Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.

  • CVE-2015-8249CriSep 28, 2017
    risk 0.73cvss 9.8epss 0.74

    The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.

  • CVE-2017-9101CriMay 21, 2017
    risk 0.73cvss 9.8epss 0.77

    import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file.

  • CVE-2021-24499CriAug 9, 2021
    risk 0.72cvss 9.8epss 0.60

    The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the…

  • CVE-2021-26828HigKEVJun 11, 2021
    risk 0.72cvss 8.8epss 0.39

    OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

  • CVE-2021-31207MedKEVMay 11, 2021
    risk 0.72cvss 6.6epss 1.00

    Microsoft Exchange Server Security Feature Bypass Vulnerability

  • CVE-2020-35489CriDec 17, 2020
    risk 0.72cvss 10.0epss 0.89

    The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.

  • CVE-2020-29597CriDec 7, 2020
    risk 0.72cvss 9.8epss 0.71

    IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server.

  • CVE-2026-0740CriApr 7, 2026
    risk 0.71cvss 9.8epss 0.58

    The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for…

  • CVE-2024-23759CriFeb 12, 2024
    risk 0.71cvss 9.8epss 0.48

    Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.

  • CVE-2023-46264CriDec 19, 2023
    risk 0.71cvss 9.8epss 0.90

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.

  • CVE-2021-43936CriDec 6, 2021
    risk 0.71cvss 10.0epss 0.36

    The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.

  • CVE-2021-37539CriSep 27, 2021
    risk 0.71cvss 9.8epss 0.93

    Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.

  • CVE-2021-36356CriAug 31, 2021
    risk 0.71cvss 9.8epss 0.54

    KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an…

  • CVE-2011-4908CriFeb 12, 2020
    risk 0.71cvss 9.8epss 0.56

    TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.

  • CVE-2020-6754CriFeb 5, 2020
    risk 0.71cvss 9.8epss 0.95

    dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g.,…