CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,314)
page 38 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-48031 | Cri | 0.64 | 9.8 | 0.01 | Nov 17, 2023 | OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restrictions and upload a .bat file by manipulating the file's magic bytes to masquerade as an allowed type. This can enable the… | ||
| CVE-2023-5601 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2023 | The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE. | ||
| CVE-2023-40050 | Cri | 0.64 | 9.9 | 0.01 | Oct 31, 2023 | Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution. | ||
| CVE-2023-45554 | Cri | 0.64 | 9.8 | 0.02 | Oct 25, 2023 | File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp. | ||
| CVE-2020-36706 | Cri | 0.64 | 9.8 | 0.02 | Oct 20, 2023 | The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and including, 6.6.0. This makes it possible for attackers to… | ||
| CVE-2023-45384 | Cri | 0.64 | 9.8 | 0.01 | Oct 19, 2023 | KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the module "Module One Page Checkout, Social Login & Mailchimp" (supercheckout), a guest can upload files with extensions .php | ||
| CVE-2023-45952 | Cri | 0.64 | 9.8 | 0.01 | Oct 17, 2023 | An arbitrary file upload vulnerability in the component ajax_link.php of lylme_spage v1.7.0 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2023-34207 | Cri | 0.64 | 9.9 | 0.01 | Oct 17, 2023 | Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate 2023 and earlier allows remote authenticated users to perform arbitrary system commands with ‘NT Authority\SYSTEM‘ privilege via a crafted ZIP archive. | ||
| CVE-2023-45856 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2023 | qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI. | ||
| CVE-2023-43269 | Cri | 0.64 | 9.8 | 0.01 | Oct 5, 2023 | pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability. | ||
| CVE-2023-44973 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2023-44009 | Cri | 0.64 | 9.8 | 0.01 | Oct 2, 2023 | File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function. | ||
| CVE-2023-44008 | Cri | 0.64 | 9.8 | 0.01 | Oct 2, 2023 | File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function. | ||
| CVE-2023-40784 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2023 | DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php. | ||
| CVE-2023-39424 | Cri | 0.64 | 9.9 | 0.01 | Sep 7, 2023 | A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication… | ||
| CVE-2023-41009 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header. | ||
| CVE-2023-40980 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2023 | File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file. | ||
| CVE-2023-41637 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2023 | An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file. | ||
| CVE-2020-18912 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2023 | An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php. | ||
| CVE-2023-38029 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or… |
- risk 0.64cvss 9.8epss 0.01
OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restrictions and upload a .bat file by manipulating the file's magic bytes to masquerade as an allowed type. This can enable the…
- risk 0.64cvss 9.8epss 0.01
The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.
- risk 0.64cvss 9.9epss 0.01
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.
- risk 0.64cvss 9.8epss 0.02
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp.
- risk 0.64cvss 9.8epss 0.02
The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and including, 6.6.0. This makes it possible for attackers to…
- risk 0.64cvss 9.8epss 0.01
KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the module "Module One Page Checkout, Social Login & Mailchimp" (supercheckout), a guest can upload files with extensions .php
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component ajax_link.php of lylme_spage v1.7.0 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.64cvss 9.9epss 0.01
Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate 2023 and earlier allows remote authenticated users to perform arbitrary system commands with ‘NT Authority\SYSTEM‘ privilege via a crafted ZIP archive.
- risk 0.64cvss 9.8epss 0.01
qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.
- risk 0.64cvss 9.8epss 0.01
pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.
- risk 0.64cvss 9.8epss 0.01
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.
- risk 0.64cvss 9.9epss 0.01
A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication…
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file.
- risk 0.64cvss 9.8epss 0.01
An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.
- risk 0.64cvss 9.8epss 0.01
Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or…