CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,314)
page 52 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-37608 | Cri | 0.64 | 9.8 | 0.06 | Aug 18, 2021 | Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at… | ||
| CVE-2020-18704 | Cri | 0.64 | 9.8 | 0.03 | Aug 16, 2021 | Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in the component 'Change Widgy Page'. | ||
| CVE-2021-38753 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2021 | An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app. | ||
| CVE-2021-29377 | Cri | 0.64 | 9.8 | 0.02 | Aug 12, 2021 | Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can be uploaded via admin.php/index/upload because app/common/service/UploadService.php mishandles fileExt. | ||
| CVE-2020-20979 | Cri | 0.64 | 9.8 | 0.02 | Aug 12, 2021 | An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code. | ||
| CVE-2020-28165 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2021 | The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function. | ||
| CVE-2020-21359 | Cri | 0.64 | 9.8 | 0.02 | Aug 11, 2021 | An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name. | ||
| CVE-2020-28088 | Cri | 0.64 | 9.8 | 0.02 | Aug 6, 2021 | An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code. | ||
| CVE-2020-19302 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2021 | An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded file suffixes to ".php". | ||
| CVE-2021-36623 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2021 | Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE. | ||
| CVE-2021-36622 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2021 | Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin panel has an upload function of profile photo accessible at http://localhost/scheduler/admin/?page=user. An attacker could upload a malicious file such as… | ||
| CVE-2021-25200 | Cri | 0.64 | 9.8 | 0.02 | Jul 30, 2021 | Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php. | ||
| CVE-2021-25208 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2021 | Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitrary code via the file upload to updatepackage.php. | ||
| CVE-2021-25206 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2021 | Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbitrary code via the file upload to Product_model.php. | ||
| CVE-2021-25203 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2021 | Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php. | ||
| CVE-2021-25207 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2021 | Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary code via the file upload to prodViewUpdate.php. | ||
| CVE-2021-25211 | Cri | 0.64 | 9.8 | 0.02 | Jul 22, 2021 | Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php. | ||
| CVE-2021-25210 | Cri | 0.64 | 9.8 | 0.01 | Jul 22, 2021 | Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php. | ||
| CVE-2021-35963 | Cri | 0.64 | 9.8 | 0.02 | Jul 19, 2021 | The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files containing malicious script to execute RCE attacks. | ||
| CVE-2021-32538 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2021 | ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further execute code unrestrictedly. |
- risk 0.64cvss 9.8epss 0.06
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at…
- risk 0.64cvss 9.8epss 0.03
Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in the component 'Change Widgy Page'.
- risk 0.64cvss 9.8epss 0.01
An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app.
- risk 0.64cvss 9.8epss 0.02
Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can be uploaded via admin.php/index/upload because app/common/service/UploadService.php mishandles fileExt.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded file suffixes to ".php".
- risk 0.64cvss 9.8epss 0.02
Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE.
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin panel has an upload function of profile photo accessible at http://localhost/scheduler/admin/?page=user. An attacker could upload a malicious file such as…
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php.
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitrary code via the file upload to updatepackage.php.
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbitrary code via the file upload to Product_model.php.
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary code via the file upload to prodViewUpdate.php.
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php.
- risk 0.64cvss 9.8epss 0.01
Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php.
- risk 0.64cvss 9.8epss 0.02
The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files containing malicious script to execute RCE attacks.
- risk 0.64cvss 9.8epss 0.02
ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further execute code unrestrictedly.