VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,339)

page 202 of 217
  • CVE-2023-39933MedMar 18, 2024
    risk 0.28cvss 4.3epss 0.00

    Insufficient verification vulnerability exists in Broadcast Mail CGI (pmc.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a user who can upload files through the product may execute an arbitrary executable file with the…

  • CVE-2023-25922MedFeb 28, 2024
    risk 0.28cvss 4.3epss 0.01

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247621.

  • CVE-2023-49715MedJan 10, 2024
    risk 0.28cvss 4.3epss 0.01

    A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution when chained with an LFI vulnerability. An attacker can send…

  • CVE-2023-6551MedJan 4, 2024
    risk 0.28cvss 5.4epss 0.00

    As a simple library, class.upload.php does not perform an in-depth check on uploaded files, allowing a stored XSS vulnerability when the default configuration is used. Developers must be aware of that fact and use extension whitelisting accompanied by forcing the server to…

  • CVE-2023-7026MedDec 21, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Lightxun IPTV Gateway up to 20231208. It has been rated as problematic. This issue affects some unknown processing of the file /ZHGXTV/index.php/admin/index/web_upload_template.html. The manipulation of the argument file leads to unrestricted upload.…

  • CVE-2023-3796MedJul 20, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in Bug Finder Foody Friend 1.0. Affected by this issue is some unknown functionality of the file /user/profile of the component Profile Picture Handler. The manipulation of the argument profile_picture leads to…

  • CVE-2022-47191MedMar 31, 2023
    risk 0.28cvss 4.3epss 0.01

    Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with modified permissions, allowing him to escalate privileges.

  • CVE-2023-22937MedFeb 14, 2023
    risk 0.28cvss 4.3epss 0.00

    In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature let a user upload lookup tables with unnecessary filename extensions. Lookup table file extensions may now be one of the following only: .csv, .csv.gz, .kmz, .kml, .mmdb, or .mmdb.gzl.

  • CVE-2022-3478MedJan 26, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible to trigger a DoS attack by uploading a malicious nuget package.

  • CVE-2022-37426MedOct 28, 2022
    risk 0.28cvss 4.3epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection.

  • CVE-2022-2872MedSep 21, 2022
    risk 0.28cvss 5.4epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.

  • CVE-2022-32065MedJul 13, 2022
    risk 0.28cvss 5.4epss 0.01

    An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.

  • CVE-2022-1811MedMay 23, 2022
    risk 0.28cvss 5.4epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.

  • CVE-2022-0950MedMar 15, 2022
    risk 0.28cvss 5.4epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4.

  • CVE-2022-0945MedMar 15, 2022
    risk 0.28cvss 5.4epss 0.01

    Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4.

  • CVE-2022-0962MedMar 14, 2022
    risk 0.28cvss 5.4epss 0.01

    Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4.

  • CVE-2022-0960MedMar 14, 2022
    risk 0.28cvss 5.4epss 0.01

    Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.

  • CVE-2022-0472MedFeb 4, 2022
    risk 0.28cvss 5.4epss 0.01

    Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9.

  • CVE-2022-23026MedJan 25, 2022
    risk 0.28cvss 4.3epss 0.01

    On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST endpoint causing an increase in…

  • CVE-2021-23001MedMar 31, 2021
    risk 0.28cvss 4.3epss 0.01

    On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, the upload functionality in BIG-IP Advanced WAF and BIG-IP ASM allows an authenticated user to upload files to the BIG-IP…