VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 39 of 216
  • CVE-2023-32757CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.

  • CVE-2023-39970CriAug 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.

  • CVE-2023-38915CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in Wolf-leo EasyAdmin8 v.1.0 allows a remote attacker to execute arbtirary code via the upload type function.

  • CVE-2020-36082CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.

  • CVE-2023-39776CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-33493CriAug 1, 2023
    risk 0.64cvss 9.8epss 0.01

    An Unrestricted Upload of File with Dangerous Type vulnerability in the Ajaxmanager File and Database explorer (ajaxmanager) module for PrestaShop through 2.3.0, allows remote attackers to upload dangerous files without restrictions.

  • CVE-2023-32225CriJul 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -  A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.

  • CVE-2023-37677CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php.

  • CVE-2023-34798CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-32637CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who can upload files through the product may execute arbitrary code on the server.

  • CVE-2023-37289CriJul 20, 2023
    risk 0.64cvss 9.8epss 0.01

    It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On-line Submission and Approval System, which allows an unauthenticated remote attacker can exploit this vulnerability without logging system…

  • CVE-2023-37839CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2023-34136CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2023-37656CriJul 11, 2023
    risk 0.64cvss 9.8epss 0.02

    WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload.

  • CVE-2023-37152CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.02

    Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.

  • CVE-2023-36969HigJul 6, 2023
    risk 0.64cvss 8.8epss 0.49

    CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.

  • CVE-2020-22153CriJul 3, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.

  • CVE-2020-22151CriJul 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.

  • CVE-2020-18432CriJun 30, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.

  • CVE-2023-34738CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Chemex through 3.7.1 is vulnerable to arbitrary file upload.