CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,434)
page 47 of 222| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-41383 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2022 | The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0. | ||
| CVE-2022-41382 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2022 | The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0. | ||
| CVE-2022-41381 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2022 | The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0. | ||
| CVE-2022-41380 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2022 | The d8s-yaml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0. | ||
| CVE-2022-40721 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2022 | Arbitrary file upload vulnerability in php uploader | ||
| CVE-2021-45790 | Cri | 0.64 | 9.8 | 0.02 | Sep 29, 2022 | An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands. | ||
| CVE-2022-37346 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2022 | EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an… | ||
| CVE-2022-40050 | Cri | 0.64 | 9.8 | 0.01 | Sep 26, 2022 | ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1. | ||
| CVE-2022-40087 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2022 | Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-40432 | Cri | 0.64 | 9.8 | 0.02 | Sep 19, 2022 | The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0. | ||
| CVE-2022-40431 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | ||
| CVE-2022-38887 | Cri | 0.64 | 9.8 | 0.02 | Sep 19, 2022 | The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38886 | Cri | 0.64 | 9.8 | 0.02 | Sep 19, 2022 | The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38885 | Cri | 0.64 | 9.8 | 0.02 | Sep 19, 2022 | The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38884 | Cri | 0.64 | 9.8 | 0.02 | Sep 19, 2022 | The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38883 | Cri | 0.64 | 9.8 | 0.02 | Sep 19, 2022 | The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38882 | Cri | 0.64 | 9.8 | 0.02 | Sep 19, 2022 | The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38881 | Cri | 0.64 | 9.8 | 0.02 | Sep 19, 2022 | The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38296 | Cri | 0.64 | 9.8 | 0.05 | Sep 12, 2022 | Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager. | ||
| CVE-2022-36557 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2022 | Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file. |
- risk 0.64cvss 9.8epss 0.01
The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-yaml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
Arbitrary file upload vulnerability in php uploader
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.
- risk 0.64cvss 9.8epss 0.01
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an…
- risk 0.64cvss 9.8epss 0.01
ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.
- risk 0.64cvss 9.8epss 0.02
Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.02
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.02
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.02
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.02
The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.02
The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.02
The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.02
The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.02
The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.05
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
- risk 0.64cvss 9.8epss 0.01
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.