CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,434)
page 49 of 222| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26634 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code execution or privilege escalation. Attackers can use these vulnerabilities to… | ||
| CVE-2021-42654 | Cri | 0.64 | 9.8 | 0.02 | May 24, 2022 | SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code. | ||
| CVE-2022-28104 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2022 | Foxit PDF Editor v11.3.1 was discovered to contain an arbitrary file upload vulnerability. | ||
| CVE-2022-29354 | Cri | 0.64 | 9.8 | 0.02 | May 16, 2022 | An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file. | ||
| CVE-2022-29353 | Cri | 0.64 | 9.8 | 0.02 | May 16, 2022 | An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted filename. | ||
| CVE-2022-29351 | Cri | 0.64 | 9.8 | 0.03 | May 16, 2022 | An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here. | ||
| CVE-2021-42967 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files. | ||
| CVE-2022-30448 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2022 | Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php. | ||
| CVE-2022-28606 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2022 | An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server. | ||
| CVE-2022-28120 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2022 | Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0 has a file upload vulnerability, which can be exploited by an attacker to gain control of the server. | ||
| CVE-2022-29347 | Cri | 0.64 | 9.8 | 0.03 | May 4, 2022 | An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file. | ||
| CVE-2022-28568 | Cri | 0.64 | 9.8 | 0.03 | May 4, 2022 | Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored. | ||
| CVE-2021-43934 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2022 | Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentially upload arbitrary files. | ||
| CVE-2021-41921 | Cri | 0.64 | 9.8 | 0.02 | Apr 28, 2022 | novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution. | ||
| CVE-2022-27468 | Cri | 0.64 | 9.8 | 0.02 | Apr 26, 2022 | Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server. | ||
| CVE-2022-27862 | Cri | 0.64 | 9.8 | 0.02 | Apr 19, 2022 | Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form. | ||
| CVE-2022-28397 | Cri | 0.64 | 9.8 | 0.04 | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this… | ||
| CVE-2022-27952 | Cri | 0.64 | 9.8 | 0.02 | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file. | ||
| CVE-2022-27263 | Cri | 0.64 | 9.8 | 0.03 | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file. | ||
| CVE-2022-27262 | Cri | 0.64 | 9.8 | 0.02 | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file. |
- risk 0.64cvss 9.8epss 0.01
SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code execution or privilege escalation. Attackers can use these vulnerabilities to…
- risk 0.64cvss 9.8epss 0.02
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
Foxit PDF Editor v11.3.1 was discovered to contain an arbitrary file upload vulnerability.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted filename.
- risk 0.64cvss 9.8epss 0.03
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here.
- risk 0.64cvss 9.8epss 0.01
Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.
- risk 0.64cvss 9.8epss 0.02
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server.
- risk 0.64cvss 9.8epss 0.01
Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0 has a file upload vulnerability, which can be exploited by an attacker to gain control of the server.
- risk 0.64cvss 9.8epss 0.03
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.03
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
- risk 0.64cvss 9.8epss 0.01
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentially upload arbitrary files.
- risk 0.64cvss 9.8epss 0.02
novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.
- risk 0.64cvss 9.8epss 0.02
Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server.
- risk 0.64cvss 9.8epss 0.02
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.
- risk 0.64cvss 9.8epss 0.04
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this…
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.
- risk 0.64cvss 9.8epss 0.03
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.