CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,434)
page 51 of 222| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24651 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2022 | sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload. | ||
| CVE-2022-25016 | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2022 | Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-25411 | Cri | 0.64 | 9.8 | 0.03 | Feb 28, 2022 | A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-24553 | Cri | 0.64 | 9.8 | 0.03 | Feb 21, 2022 | An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution. | ||
| CVE-2021-46036 | Cri | 0.64 | 9.8 | 0.04 | Feb 18, 2022 | An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code. | ||
| CVE-2022-24984 | Cri | 0.64 | 9.8 | 0.03 | Feb 16, 2022 | Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur on the client side, and because not all… | ||
| CVE-2022-23390 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2022 | An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files. | ||
| CVE-2021-22803 | Cri | 0.64 | 9.8 | 0.02 | Feb 11, 2022 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network.… | ||
| CVE-2020-13675 | Cri | 0.64 | 9.8 | 0.01 | Feb 11, 2022 | Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by… | ||
| CVE-2021-46428 | Cri | 0.64 | 9.8 | 0.03 | Jan 27, 2022 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php. | ||
| CVE-2021-46386 | Cri | 0.64 | 9.8 | 0.03 | Jan 26, 2022 | File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload. | ||
| CVE-2021-46033 | Cri | 0.64 | 9.8 | 0.01 | Jan 25, 2022 | In ForestBlog, as of 2021-12-28, File upload can bypass verification. | ||
| CVE-2022-23315 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do. | ||
| CVE-2022-22929 | Cri | 0.64 | 9.8 | 0.03 | Jan 21, 2022 | MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file. | ||
| CVE-2021-46013 | Cri | 0.64 | 9.8 | 0.03 | Jan 18, 2022 | An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets… | ||
| CVE-2021-38697 | Cri | 0.64 | 9.8 | 0.03 | Jan 18, 2022 | SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which can lead to arbitrary code execution. | ||
| CVE-2021-45411 | Cri | 0.64 | 9.8 | 0.04 | Jan 12, 2022 | In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution. | ||
| CVE-2021-44031 | Cri | 0.64 | 9.8 | 0.02 | Dec 22, 2021 | An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication remote code execution. An attacker could upload a .ASP file to reside at… | ||
| CVE-2021-44164 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2021 | Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of… | ||
| CVE-2021-44159 | Cri | 0.64 | 9.8 | 0.03 | Dec 20, 2021 | 4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack. |
- risk 0.64cvss 9.8epss 0.03
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload.
- risk 0.64cvss 9.8epss 0.02
Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.03
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.03
An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution.
- risk 0.64cvss 9.8epss 0.04
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.03
Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur on the client side, and because not all…
- risk 0.64cvss 9.8epss 0.01
An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files.
- risk 0.64cvss 9.8epss 0.02
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network.…
- risk 0.64cvss 9.8epss 0.01
Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by…
- risk 0.64cvss 9.8epss 0.03
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php.
- risk 0.64cvss 9.8epss 0.03
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.
- risk 0.64cvss 9.8epss 0.01
In ForestBlog, as of 2021-12-28, File upload can bypass verification.
- risk 0.64cvss 9.8epss 0.02
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
- risk 0.64cvss 9.8epss 0.03
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.
- risk 0.64cvss 9.8epss 0.03
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets…
- risk 0.64cvss 9.8epss 0.03
SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which can lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.04
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication remote code execution. An attacker could upload a .ASP file to reside at…
- risk 0.64cvss 9.8epss 0.02
Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without authentication, in order to take control of…
- risk 0.64cvss 9.8epss 0.03
4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.