CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,434)
page 52 of 222| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40883 | Cri | 0.64 | 9.8 | 0.03 | Dec 14, 2021 | A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins. | ||
| CVE-2021-43117 | Cri | 0.64 | 9.8 | 0.02 | Dec 13, 2021 | fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access. | ||
| CVE-2021-42125 | Hig | 0.64 | 8.8 | 0.82 | Dec 7, 2021 | An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files. | ||
| CVE-2021-42099 | Cri | 0.64 | 9.8 | 0.07 | Nov 30, 2021 | Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution. | ||
| CVE-2021-44093 | Cri | 0.64 | 9.8 | 0.03 | Nov 28, 2021 | A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell | ||
| CVE-2021-41833 | Cri | 0.64 | 9.8 | 0.08 | Nov 11, 2021 | Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution. | ||
| CVE-2021-28023 | Cri | 0.64 | 9.8 | 0.01 | Nov 8, 2021 | Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by uploading a zip that extracts files in relative paths. | ||
| CVE-2020-18261 | Cri | 0.64 | 9.8 | 0.01 | Nov 3, 2021 | An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands. | ||
| CVE-2021-26740 | Cri | 0.64 | 9.8 | 0.02 | Nov 1, 2021 | Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code. | ||
| CVE-2021-41646 | Cri | 0.64 | 9.8 | 0.07 | Oct 29, 2021 | Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters.. | ||
| CVE-2021-41644 | Cri | 0.64 | 9.8 | 0.03 | Oct 29, 2021 | Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters. | ||
| CVE-2021-41643 | Cri | 0.64 | 9.8 | 0.05 | Oct 29, 2021 | Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field. | ||
| CVE-2021-36548 | Cri | 0.64 | 9.8 | 0.03 | Oct 28, 2021 | A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file. | ||
| CVE-2021-36547 | Cri | 0.64 | 9.8 | 0.03 | Oct 28, 2021 | A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file. | ||
| CVE-2021-20125 | Cri | 0.64 | 9.8 | 0.04 | Oct 13, 2021 | An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could leverage this vulnerability to upload files to any location on the target operating… | ||
| CVE-2021-41566 | Cri | 0.64 | 9.8 | 0.02 | Oct 8, 2021 | The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in. | ||
| CVE-2021-37931 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37930 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37929 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37928 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. |
- risk 0.64cvss 9.8epss 0.03
A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.
- risk 0.64cvss 9.8epss 0.02
fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.
- risk 0.64cvss 8.8epss 0.82
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
- risk 0.64cvss 9.8epss 0.03
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell
- risk 0.64cvss 9.8epss 0.08
Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
- risk 0.64cvss 9.8epss 0.01
Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by uploading a zip that extracts files in relative paths.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.07
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..
- risk 0.64cvss 9.8epss 0.03
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.
- risk 0.64cvss 9.8epss 0.05
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.
- risk 0.64cvss 9.8epss 0.03
A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.03
A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.04
An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could leverage this vulnerability to upload files to any location on the target operating…
- risk 0.64cvss 9.8epss 0.02
The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.