CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,314)
page 42 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-3682 | Cri | 0.64 | 9.9 | 0.01 | Mar 28, 2023 | A vulnerability exists in the SDM600 file permission validation. An attacker could exploit the vulnerability by gaining access to the system and uploading a specially crafted message to the system node, which could result in Arbitrary code Executing. This issue affects: All… | ||
| CVE-2023-25909 | Cri | 0.64 | 9.8 | 0.01 | Mar 27, 2023 | HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service. | ||
| CVE-2023-27757 | Cri | 0.64 | 9.8 | 0.01 | Mar 15, 2023 | An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file. | ||
| CVE-2021-33352 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field. | ||
| CVE-2023-26949 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2023 | An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2021-33224 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2023 | File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file. | ||
| CVE-2022-39983 | Cri | 0.64 | 9.8 | 0.01 | Feb 22, 2023 | File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code. | ||
| CVE-2022-41217 | Cri | 0.64 | 9.8 | 0.01 | Feb 22, 2023 | Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage. | ||
| CVE-2021-35261 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint. | ||
| CVE-2023-24646 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2023 | An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-45527 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2023 | File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory. | ||
| CVE-2023-24202 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php. | ||
| CVE-2022-48079 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2023 | Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system. | ||
| CVE-2022-42971 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2023 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022… | ||
| CVE-2023-0587 | Cri | 0.64 | 9.1 | 0.60 | Feb 1, 2023 | A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the… | ||
| CVE-2022-47769 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2023 | An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell. | ||
| CVE-2022-47854 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2023 | i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php. | ||
| CVE-2022-48006 | Cri | 0.64 | 9.8 | 0.01 | Jan 30, 2023 | An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploited via manipulation of the upext variable at /include/Model/Upload.php. | ||
| CVE-2022-48008 | Cri | 0.64 | 9.8 | 0.01 | Jan 27, 2023 | An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-40037 | Cri | 0.64 | 9.8 | 0.02 | Jan 26, 2023 | An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile. |
- risk 0.64cvss 9.9epss 0.01
A vulnerability exists in the SDM600 file permission validation. An attacker could exploit the vulnerability by gaining access to the system and uploading a specially crafted message to the system node, which could result in Arbitrary code Executing. This issue affects: All…
- risk 0.64cvss 9.8epss 0.01
HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file.
- risk 0.64cvss 9.8epss 0.01
An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.
- risk 0.64cvss 9.8epss 0.01
File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.
- risk 0.64cvss 9.8epss 0.01
File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.
- risk 0.64cvss 9.8epss 0.01
Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.
- risk 0.64cvss 9.8epss 0.01
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022…
- risk 0.64cvss 9.1epss 0.60
A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the…
- risk 0.64cvss 9.8epss 0.01
An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.
- risk 0.64cvss 9.8epss 0.01
i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploited via manipulation of the upext variable at /include/Model/Upload.php.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.02
An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile.