VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 40 of 216
  • CVE-2022-44276CriJun 28, 2023
    risk 0.64cvss 9.8epss 0.02

    In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.

  • CVE-2023-36097CriJun 22, 2023
    risk 0.64cvss 9.8epss 0.01

    funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.

  • CVE-2020-21474CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.

  • CVE-2020-20735CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.

  • CVE-2020-20718CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.

  • CVE-2023-32753CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.

  • CVE-2023-32752CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system…

  • CVE-2023-34944CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.

  • CVE-2023-31541CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.

  • CVE-2023-3049CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.04

    Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection. This issue affects Lockcell: before 15.

  • CVE-2020-36705CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.07

    The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible for unauthenticated attackers to upload arbitrary files on…

  • CVE-2019-25138CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possible for unauthenticated attackers to upload arbitrary files…

  • CVE-2016-15033CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the delete-all-comments.php file in versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to upload arbitrary…

  • CVE-2023-29631CriJun 5, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.

  • CVE-2023-33386CriJun 5, 2023
    risk 0.64cvss 9.8epss 0.01

    MarsCTF 1.2.1 has an arbitrary file upload vulnerability in the interface for uploading attachments in the background.

  • CVE-2023-33508CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).

  • CVE-2023-29721CriMay 24, 2023
    risk 0.64cvss 9.8epss 0.01

    SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution.

  • CVE-2023-28409CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file.

  • CVE-2023-27397CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.

  • CVE-2023-2712CriMay 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server. This issue affects Rental Module: before 23.05.15.