VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 48 of 216
  • CVE-2022-27468CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.02

    Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server.

  • CVE-2022-27862CriApr 19, 2022
    risk 0.64cvss 9.8epss 0.02

    Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.

  • CVE-2022-28397CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.03

    An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this…

  • CVE-2022-27952CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.

  • CVE-2022-27263CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.03

    An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2022-27262CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2022-27260CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.03

    An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.

  • CVE-2022-27140CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.03

    An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted PHP file. NOTE: the vendor's position is that the observed behavior can only occur with "intentional misusing of the API": the…

  • CVE-2022-27139CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.04

    An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as outlined in Ghost's security documentation, upload of SVGs is only possible by trusted authenticated…

  • CVE-2022-27477CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.

  • CVE-2022-27131CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability at /zbzedit/php/zbz.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27129CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability at /admin/ajax.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27047CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.01

    mogu_blog_cms 5.2 suffers from upload arbitrary files without any limitation.

  • CVE-2022-27357CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.03

    Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27351CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.03

    Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-24136CriMar 31, 2022
    risk 0.64cvss 9.8epss 0.02

    Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an attacker can upload any PHP file, and then execute it.

  • CVE-2022-26645CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.03

    A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.

  • CVE-2021-45865CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality.

  • CVE-2022-23880CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2021-27428CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.01

    GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade…