VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 34 of 222
  • CVE-2024-49260CriOct 16, 2024
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery allows Code Injection.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a through <= 1.5.7.

  • CVE-2024-48035CriOct 16, 2024
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in takayukii ACF Images Search And Insert acf-images-search-and-insert allows Upload a Web Shell to a Web Server.This issue affects ACF Images Search And Insert: from n/a through <= 1.1.4.

  • CVE-2024-48034CriOct 16, 2024
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in fliperrr Creates 3D Flipbook, PDF Flipbook create-flipbook-from-pdf allows Upload a Web Shell to a Web Server.This issue affects Creates 3D Flipbook, PDF Flipbook: from n/a through <= 1.2.

  • CVE-2024-48027CriOct 16, 2024
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing external-featured-image-from-bing allows Upload a Web Shell to a Web Server.This issue affects External featured image from bing: from n/a through <= 1.0.2.

  • CVE-2016-15042CriOct 16, 2024
    risk 0.64cvss 9.8epss 0.06

    The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This…

  • CVE-2021-4449CriOct 16, 2024
    risk 0.64cvss 9.8epss 0.05

    The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's…

  • CVE-2021-4443CriOct 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, 2.0.6 via the compiler_save AJAX action. This makes it possible for unauthenticated attackers to create arbitrary PHP files that can be used to execute…

  • CVE-2024-48782CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via the application only detecting the extension of image files in the front-end.

  • CVE-2024-48781CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.

  • CVE-2024-46088CriOct 11, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer Resource Management System v2002 to v2024 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-9108CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.01

    The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to upload…

  • CVE-2023-26686CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.

  • CVE-2024-46101CriSep 20, 2024
    risk 0.64cvss 9.8epss 0.00

    GDidees CMS <= v3.9.1 has a file upload vulnerability.

  • CVE-2024-40125CriSep 19, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitrary code via uploading a crafted PHP file to the upload endpoint.

  • CVE-2024-46377CriSep 18, 2024
    risk 0.64cvss 9.8epss 0.01

    Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.

  • CVE-2024-27115CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.05

    A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the…

  • CVE-2024-8463CriSep 5, 2024
    risk 0.64cvss 9.9epss 0.01

    File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell.

  • CVE-2024-45076CriSep 4, 2024
    risk 0.64cvss 9.9epss 0.01

    IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying operating system.

  • CVE-2024-42777CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-42563CriAug 20, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.