VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 46 of 216
  • CVE-2022-38884CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38883CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38882CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38881CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38296CriSep 12, 2022
    risk 0.64cvss 9.8epss 0.04

    Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

  • CVE-2022-36557CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.

  • CVE-2022-37181CriAug 24, 2022
    risk 0.64cvss 9.8epss 0.01

    72crm 9.0 has an Arbitrary file upload vulnerability.

  • CVE-2022-35150CriAug 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.

  • CVE-2022-2180CriAug 15, 2022
    risk 0.64cvss 9.8epss 0.02

    The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution…

  • CVE-2022-35426CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.01

    UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.

  • CVE-2022-34613CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.02

    Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file.

  • CVE-2022-34496CriJul 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.

  • CVE-2022-28369CriJul 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-operation of the crtcrpc JSON listener (found at /lib/functions/wnc_jsonsh/crtcmode.sh) A remote attacker on the local network can provide a…

  • CVE-2022-30216HigJul 12, 2022
    risk 0.64cvss 8.8epss 0.89

    Windows Server Service Tampering Vulnerability

  • CVE-2021-29281CriJul 7, 2022
    risk 0.64cvss 9.8epss 0.02

    File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.

  • CVE-2022-32413CriJul 5, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2022-31943CriJul 1, 2022
    risk 0.64cvss 9.8epss 0.02

    MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.

  • CVE-2021-38945CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238.

  • CVE-2021-40954CriJun 23, 2022
    risk 0.64cvss 9.8epss 0.02

    Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.

  • CVE-2022-31374CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file.