VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 49 of 216
  • CVE-2021-39384CriMar 20, 2022
    risk 0.64cvss 9.8epss 0.01

    DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java.

  • CVE-2021-45835CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.03

    The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through documents.php, which may be used to execute malicious code or lead to code execution.

  • CVE-2021-45834CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.

  • CVE-2021-45040CriMar 17, 2022
    risk 0.64cvss 9.8epss 0.03

    The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the uploads route.

  • CVE-2022-25495CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.

  • CVE-2022-24652CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload.

  • CVE-2022-24651CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload.

  • CVE-2022-25016CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.02

    Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-25411CriFeb 28, 2022
    risk 0.64cvss 9.8epss 0.03

    A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-24553CriFeb 21, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution.

  • CVE-2021-46036CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.04

    An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.

  • CVE-2022-24984CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.03

    Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur on the client side, and because not all…

  • CVE-2022-23390CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files.

  • CVE-2021-22803CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.02

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network.…

  • CVE-2020-13675CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by…

  • CVE-2021-46428CriJan 27, 2022
    risk 0.64cvss 9.8epss 0.03

    A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php.

  • CVE-2021-46386CriJan 26, 2022
    risk 0.64cvss 9.8epss 0.03

    File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.

  • CVE-2021-46033CriJan 25, 2022
    risk 0.64cvss 9.8epss 0.01

    In ForestBlog, as of 2021-12-28, File upload can bypass verification.

  • CVE-2022-23315CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.02

    MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.

  • CVE-2022-22929CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.03

    MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.