VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 44 of 222
  • CVE-2022-39983CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code.

  • CVE-2022-41217CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.

  • CVE-2021-35261CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.

  • CVE-2023-24646CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-45527CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory.

  • CVE-2023-24202CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.

  • CVE-2022-48079CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.

  • CVE-2022-42971CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022…

  • CVE-2023-0587CriFeb 1, 2023
    risk 0.64cvss 9.1epss 0.60

    A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the…

  • CVE-2022-47769CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.

  • CVE-2022-47854CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php.

  • CVE-2022-48006CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploited via manipulation of the upext variable at /include/Model/Upload.php.

  • CVE-2022-48008CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-40037CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile.

  • CVE-2022-45896CriDec 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/ProcessUpload2. This leads to remote code execution.

  • CVE-2022-46493CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Default version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/download_img.

  • CVE-2022-46102CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php

  • CVE-2022-45966CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.

  • CVE-2022-41267CriDec 13, 2022
    risk 0.64cvss 9.9epss 0.01

    SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objects server at the operating system level, enabling the attacker to take full control of the system causing a high impact on…

  • CVE-2022-36431CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.