VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 40 of 222
  • CVE-2023-34207CriOct 17, 2023
    risk 0.64cvss 9.9epss 0.01

    Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate 2023 and earlier allows remote authenticated users to perform arbitrary system commands with ‘NT Authority\SYSTEM‘ privilege via a crafted ZIP archive.

  • CVE-2023-45856CriOct 14, 2023
    risk 0.64cvss 9.8epss 0.01

    qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.

  • CVE-2023-43269CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.

  • CVE-2023-44973CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2023-44009CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.

  • CVE-2023-44008CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

  • CVE-2023-40784CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.

  • CVE-2023-39424CriSep 7, 2023
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication…

  • CVE-2023-41009CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.02

    File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header.

  • CVE-2023-40980CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.

  • CVE-2023-41637CriAug 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file.

  • CVE-2020-18912CriAug 29, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.

  • CVE-2023-38029CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or…

  • CVE-2023-32757CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.

  • CVE-2023-39970CriAug 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.

  • CVE-2023-38915CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in Wolf-leo EasyAdmin8 v.1.0 allows a remote attacker to execute arbtirary code via the upload type function.

  • CVE-2020-36082CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.

  • CVE-2023-39776CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-33493CriAug 1, 2023
    risk 0.64cvss 9.8epss 0.01

    An Unrestricted Upload of File with Dangerous Type vulnerability in the Ajaxmanager File and Database explorer (ajaxmanager) module for PrestaShop through 2.3.0, allows remote attackers to upload dangerous files without restrictions.

  • CVE-2023-32225CriJul 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -  A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.