CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,434)
page 54 of 222| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-21359 | Cri | 0.64 | 9.8 | 0.02 | Aug 11, 2021 | An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name. | ||
| CVE-2020-28088 | Cri | 0.64 | 9.8 | 0.02 | Aug 6, 2021 | An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code. | ||
| CVE-2020-19302 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2021 | An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded file suffixes to ".php". | ||
| CVE-2021-36623 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2021 | Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE. | ||
| CVE-2021-36622 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2021 | Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin panel has an upload function of profile photo accessible at http://localhost/scheduler/admin/?page=user. An attacker could upload a malicious file such as… | ||
| CVE-2021-25200 | Cri | 0.64 | 9.8 | 0.02 | Jul 30, 2021 | Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php. | ||
| CVE-2021-25208 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2021 | Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitrary code via the file upload to updatepackage.php. | ||
| CVE-2021-25206 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2021 | Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbitrary code via the file upload to Product_model.php. | ||
| CVE-2021-25203 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2021 | Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php. | ||
| CVE-2021-25207 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2021 | Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary code via the file upload to prodViewUpdate.php. | ||
| CVE-2021-25211 | Cri | 0.64 | 9.8 | 0.02 | Jul 22, 2021 | Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php. | ||
| CVE-2021-25210 | Cri | 0.64 | 9.8 | 0.01 | Jul 22, 2021 | Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php. | ||
| CVE-2021-35963 | Cri | 0.64 | 9.8 | 0.02 | Jul 19, 2021 | The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files containing malicious script to execute RCE attacks. | ||
| CVE-2021-32538 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2021 | ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further execute code unrestrictedly. | ||
| CVE-2021-34624 | Cri | 0.64 | 9.8 | 0.07 | Jul 7, 2021 | A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 -… | ||
| CVE-2021-34623 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2021 | A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 -… | ||
| CVE-2020-22249 | Cri | 0.64 | 9.8 | 0.03 | Jul 6, 2021 | Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which… | ||
| CVE-2021-34074 | Cri | 0.64 | 9.8 | 0.07 | Jun 25, 2021 | PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests. | ||
| CVE-2020-21786 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2021 | In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php. | ||
| CVE-2020-21787 | Cri | 0.64 | 9.8 | 0.02 | Jun 24, 2021 | CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php. |
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded file suffixes to ".php".
- risk 0.64cvss 9.8epss 0.02
Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE.
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin panel has an upload function of profile photo accessible at http://localhost/scheduler/admin/?page=user. An attacker could upload a malicious file such as…
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php.
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitrary code via the file upload to updatepackage.php.
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbitrary code via the file upload to Product_model.php.
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary code via the file upload to prodViewUpdate.php.
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php.
- risk 0.64cvss 9.8epss 0.01
Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php.
- risk 0.64cvss 9.8epss 0.02
The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files containing malicious script to execute RCE attacks.
- risk 0.64cvss 9.8epss 0.02
ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further execute code unrestrictedly.
- risk 0.64cvss 9.8epss 0.07
A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 -…
- risk 0.64cvss 9.8epss 0.02
A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 -…
- risk 0.64cvss 9.8epss 0.03
Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which…
- risk 0.64cvss 9.8epss 0.07
PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.
- risk 0.64cvss 9.8epss 0.01
In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php.
- risk 0.64cvss 9.8epss 0.02
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.