CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,434)
page 41 of 222| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-37677 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2023 | Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php. | ||
| CVE-2023-34798 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2023 | An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2023-32637 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2023 | GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who can upload files through the product may execute arbitrary code on the server. | ||
| CVE-2023-37289 | Cri | 0.64 | 9.8 | 0.01 | Jul 20, 2023 | It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On-line Submission and Approval System, which allows an unauthenticated remote attacker can exploit this vulnerability without logging system… | ||
| CVE-2023-37839 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2023 | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2023-34136 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2023 | Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | ||
| CVE-2023-37656 | Cri | 0.64 | 9.8 | 0.02 | Jul 11, 2023 | WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload. | ||
| CVE-2023-37152 | Cri | 0.64 | 9.8 | 0.02 | Jul 10, 2023 | Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability. | ||
| CVE-2023-36969 | Hig | 0.64 | 8.8 | 0.49 | Jul 6, 2023 | CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function. | ||
| CVE-2020-22153 | Cri | 0.64 | 9.8 | 0.01 | Jul 3, 2023 | File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function. | ||
| CVE-2020-22151 | Cri | 0.64 | 9.8 | 0.01 | Jul 3, 2023 | Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function. | ||
| CVE-2020-18432 | Cri | 0.64 | 9.8 | 0.01 | Jun 30, 2023 | File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges. | ||
| CVE-2023-34738 | Cri | 0.64 | 9.8 | 0.01 | Jun 29, 2023 | Chemex through 3.7.1 is vulnerable to arbitrary file upload. | ||
| CVE-2022-44276 | Cri | 0.64 | 9.8 | 0.02 | Jun 28, 2023 | In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE. | ||
| CVE-2023-36097 | Cri | 0.64 | 9.8 | 0.01 | Jun 22, 2023 | funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install. | ||
| CVE-2020-21474 | Cri | 0.64 | 9.8 | 0.01 | Jun 20, 2023 | File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter. | ||
| CVE-2020-20735 | Cri | 0.64 | 9.8 | 0.01 | Jun 20, 2023 | File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter. | ||
| CVE-2020-20718 | Cri | 0.64 | 9.8 | 0.01 | Jun 20, 2023 | File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter. | ||
| CVE-2023-32753 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service. | ||
| CVE-2023-32752 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system… |
- risk 0.64cvss 9.8epss 0.01
Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.64cvss 9.8epss 0.01
GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who can upload files through the product may execute arbitrary code on the server.
- risk 0.64cvss 9.8epss 0.01
It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On-line Submission and Approval System, which allows an unauthenticated remote attacker can exploit this vulnerability without logging system…
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
- risk 0.64cvss 9.8epss 0.02
WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload.
- risk 0.64cvss 9.8epss 0.02
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.
- risk 0.64cvss 8.8epss 0.49
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.
- risk 0.64cvss 9.8epss 0.01
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
- risk 0.64cvss 9.8epss 0.01
Chemex through 3.7.1 is vulnerable to arbitrary file upload.
- risk 0.64cvss 9.8epss 0.02
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
- risk 0.64cvss 9.8epss 0.01
funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.
- risk 0.64cvss 9.8epss 0.01
OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.
- risk 0.64cvss 9.8epss 0.01
L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system…