VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 38 of 216
  • CVE-2023-48031CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restrictions and upload a .bat file by manipulating the file's magic bytes to masquerade as an allowed type. This can enable the…

  • CVE-2023-5601CriNov 6, 2023
    risk 0.64cvss 9.8epss 0.01

    The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.

  • CVE-2023-40050CriOct 31, 2023
    risk 0.64cvss 9.9epss 0.01

    Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.

  • CVE-2023-45554CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp.

  • CVE-2020-36706CriOct 20, 2023
    risk 0.64cvss 9.8epss 0.02

    The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and including, 6.6.0. This makes it possible for attackers to…

  • CVE-2023-45384CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.01

    KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the module "Module One Page Checkout, Social Login & Mailchimp" (supercheckout), a guest can upload files with extensions .php

  • CVE-2023-45952CriOct 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component ajax_link.php of lylme_spage v1.7.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-34207CriOct 17, 2023
    risk 0.64cvss 9.9epss 0.01

    Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate 2023 and earlier allows remote authenticated users to perform arbitrary system commands with ‘NT Authority\SYSTEM‘ privilege via a crafted ZIP archive.

  • CVE-2023-45856CriOct 14, 2023
    risk 0.64cvss 9.8epss 0.01

    qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.

  • CVE-2023-43269CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.

  • CVE-2023-44973CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2023-44009CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.

  • CVE-2023-44008CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

  • CVE-2023-40784CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.

  • CVE-2023-39424CriSep 7, 2023
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication…

  • CVE-2023-41009CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header.

  • CVE-2023-40980CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.

  • CVE-2023-41637CriAug 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file.

  • CVE-2020-18912CriAug 29, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.

  • CVE-2023-38029CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or…