VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 42 of 216
  • CVE-2022-3682CriMar 28, 2023
    risk 0.64cvss 9.9epss 0.01

    A vulnerability exists in the SDM600 file permission validation. An attacker could exploit the vulnerability by gaining access to the system and uploading a specially crafted message to the system node, which could result in Arbitrary code Executing. This issue affects: All…

  • CVE-2023-25909CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.01

    HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service.

  • CVE-2023-27757CriMar 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file.

  • CVE-2021-33352CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field.

  • CVE-2023-26949CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2021-33224CriFeb 24, 2023
    risk 0.64cvss 9.8epss 0.01

    File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.

  • CVE-2022-39983CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code.

  • CVE-2022-41217CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.

  • CVE-2021-35261CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.

  • CVE-2023-24646CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-45527CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory.

  • CVE-2023-24202CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.

  • CVE-2022-48079CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.

  • CVE-2022-42971CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022…

  • CVE-2023-0587CriFeb 1, 2023
    risk 0.64cvss 9.1epss 0.60

    A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the…

  • CVE-2022-47769CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.

  • CVE-2022-47854CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php.

  • CVE-2022-48006CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploited via manipulation of the upext variable at /include/Model/Upload.php.

  • CVE-2022-48008CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-40037CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile.