VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 43 of 216
  • CVE-2022-45896CriDec 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/ProcessUpload2. This leads to remote code execution.

  • CVE-2022-46493CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Default version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/download_img.

  • CVE-2022-46102CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php

  • CVE-2022-45966CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.

  • CVE-2022-41267CriDec 13, 2022
    risk 0.64cvss 9.9epss 0.01

    SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objects server at the operating system level, enabling the attacker to take full control of the system causing a high impact on…

  • CVE-2022-36431CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.

  • CVE-2022-44354CriNov 29, 2022
    risk 0.64cvss 9.8epss 0.02

    SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.

  • CVE-2022-44401CriNov 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.

  • CVE-2022-44400CriNov 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.

  • CVE-2022-45476CriNov 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload.

  • CVE-2022-41705CriNov 25, 2022
    risk 0.64cvss 9.8epss 0.02

    Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.

  • CVE-2020-23591CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " which can "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse…

  • CVE-2022-42698CriNov 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Unauth. Arbitrary File Upload vulnerability in WordPress Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.

  • CVE-2022-40200CriNov 17, 2022
    risk 0.64cvss 9.9epss 0.01

    Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.

  • CVE-2022-43234CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-43265CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-43074CriNov 10, 2022
    risk 0.64cvss 9.8epss 0.01

    AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-39036CriNov 10, 2022
    risk 0.64cvss 9.8epss 0.01

    The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary file and execute arbitrary code to manipulate system or disrupt service.

  • CVE-2022-40797CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.03

    Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)

  • CVE-2022-44054CriNov 7, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-utility package. The affected version of d8s-htm is 0.1.0.