VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 50 of 222
  • CVE-2022-27260CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.03

    An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.

  • CVE-2022-27140CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.03

    An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted PHP file. NOTE: the vendor's position is that the observed behavior can only occur with "intentional misusing of the API": the…

  • CVE-2022-27139CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.04

    An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as outlined in Ghost's security documentation, upload of SVGs is only possible by trusted authenticated…

  • CVE-2022-27477CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.

  • CVE-2022-27131CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability at /zbzedit/php/zbz.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27129CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability at /admin/ajax.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27047CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.01

    mogu_blog_cms 5.2 suffers from upload arbitrary files without any limitation.

  • CVE-2022-27357CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.04

    Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27351CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.03

    Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-24136CriMar 31, 2022
    risk 0.64cvss 9.8epss 0.02

    Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an attacker can upload any PHP file, and then execute it.

  • CVE-2022-26645CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.03

    A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.

  • CVE-2021-45865CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality.

  • CVE-2022-23880CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2021-27428CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.01

    GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade…

  • CVE-2021-39384CriMar 20, 2022
    risk 0.64cvss 9.8epss 0.01

    DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java.

  • CVE-2021-45835CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.03

    The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through documents.php, which may be used to execute malicious code or lead to code execution.

  • CVE-2021-45834CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.

  • CVE-2021-45040CriMar 17, 2022
    risk 0.64cvss 9.8epss 0.03

    The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the uploads route.

  • CVE-2022-25495CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.

  • CVE-2022-24652CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload.