VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 47 of 222
  • CVE-2022-41383CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

  • CVE-2022-41382CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

  • CVE-2022-41381CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

  • CVE-2022-41380CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-yaml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

  • CVE-2022-40721CriOct 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Arbitrary file upload vulnerability in php uploader

  • CVE-2021-45790CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.

  • CVE-2022-37346CriSep 27, 2022
    risk 0.64cvss 9.8epss 0.01

    EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an…

  • CVE-2022-40050CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.01

    ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.

  • CVE-2022-40087CriSep 22, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-40432CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0.

  • CVE-2022-40431CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

  • CVE-2022-38887CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38886CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38885CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38884CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38883CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38882CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38881CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38296CriSep 12, 2022
    risk 0.64cvss 9.8epss 0.05

    Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

  • CVE-2022-36557CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.