VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 41 of 222
  • CVE-2023-37677CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php.

  • CVE-2023-34798CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-32637CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who can upload files through the product may execute arbitrary code on the server.

  • CVE-2023-37289CriJul 20, 2023
    risk 0.64cvss 9.8epss 0.01

    It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On-line Submission and Approval System, which allows an unauthenticated remote attacker can exploit this vulnerability without logging system…

  • CVE-2023-37839CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2023-34136CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2023-37656CriJul 11, 2023
    risk 0.64cvss 9.8epss 0.02

    WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload.

  • CVE-2023-37152CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.02

    Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.

  • CVE-2023-36969HigJul 6, 2023
    risk 0.64cvss 8.8epss 0.49

    CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.

  • CVE-2020-22153CriJul 3, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.

  • CVE-2020-22151CriJul 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.

  • CVE-2020-18432CriJun 30, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.

  • CVE-2023-34738CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Chemex through 3.7.1 is vulnerable to arbitrary file upload.

  • CVE-2022-44276CriJun 28, 2023
    risk 0.64cvss 9.8epss 0.02

    In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.

  • CVE-2023-36097CriJun 22, 2023
    risk 0.64cvss 9.8epss 0.01

    funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.

  • CVE-2020-21474CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.

  • CVE-2020-20735CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.

  • CVE-2020-20718CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.

  • CVE-2023-32753CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.

  • CVE-2023-32752CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system…