VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 33 of 216
  • CVE-2024-40125CriSep 19, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitrary code via uploading a crafted PHP file to the upload endpoint.

  • CVE-2024-46377CriSep 18, 2024
    risk 0.64cvss 9.8epss 0.01

    Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.

  • CVE-2024-27115CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.05

    A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the…

  • CVE-2024-8463CriSep 5, 2024
    risk 0.64cvss 9.9epss 0.01

    File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell.

  • CVE-2024-45076CriSep 4, 2024
    risk 0.64cvss 9.9epss 0.01

    IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying operating system.

  • CVE-2024-42777CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-42563CriAug 20, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.

  • CVE-2024-43249CriAug 19, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form Pro: from n/a through 2.6.4.

  • CVE-2024-41577CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.

  • CVE-2024-40394CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the component ajax.php.

  • CVE-2024-40425CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via the contorller/common.php component.

  • CVE-2024-37424CriJul 9, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Automattic Newspack Blocks allows Upload a Web Shell to a Web Server.This issue affects Newspack Blocks: from n/a through 3.0.8.

  • CVE-2024-37420CriJul 9, 2024
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in WPZita Zita Elementor Site Library allows Upload a Web Shell to a Web Server.This issue affects Zita Elementor Site Library: from n/a through 1.6.1.

  • CVE-2024-37418CriJul 9, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.6.

  • CVE-2024-6314CriJul 9, 2024
    risk 0.64cvss 9.8epss 0.01

    The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process_image_upload' function in versions up to, and including, 2.2.7. This makes it possible for unauthenticated attackers to upload arbitrary…

  • CVE-2024-6313CriJul 9, 2024
    risk 0.64cvss 9.8epss 0.01

    The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' function in versions up to, and including, 2.2.9. This makes it possible for unauthenticated attackers to upload arbitrary files…

  • CVE-2024-27903CriJul 8, 2024
    risk 0.64cvss 9.8epss 0.09

    OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

  • CVE-2024-37762CriJul 1, 2024
    risk 0.64cvss 9.9epss 0.01

    MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

  • CVE-2024-35527CriJun 25, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in /fileupload/upload.cfm in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to execute arbitrary code via uploading a crafted .cfm file.

  • CVE-2024-4197CriJun 25, 2024
    risk 0.64cvss 9.9epss 0.01

    An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.