VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 92 of 216
  • CVE-2023-44061HigOct 6, 2023
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary code via the upload function in the edit profile component.

  • CVE-2023-43321HigOct 4, 2023
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbitrary code via the wget function in the /sbin/cloudadmin.sh component.

  • CVE-2023-4097HigOct 3, 2023
    risk 0.57cvss 8.8epss 0.01

    The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attacker to log into the application with a valid username.

  • CVE-2023-5227CriSep 30, 2023
    risk 0.57cvss 9.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

  • CVE-2023-43740HigSep 28, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

  • CVE-2023-43226HigSep 28, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2023-42335HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.01

    Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the add attachment function in the New Expense component.

  • CVE-2023-42331HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.01

    A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component.

  • CVE-2023-38887HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.

  • CVE-2023-36319HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.02

    File Upload vulnerability in Openupload Stable v.0.4.3 allows a remote attacker to execute arbitrary code via the action parameter of the compress-inc.php file.

  • CVE-2023-42180HigSep 14, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the /user/upload component of lenosp 1.0-1.2.0 allows attackers to execute html code via a crafted JPG file.

  • CVE-2023-42472HigSep 12, 2023
    risk 0.57cvss 8.7epss 0.01

    Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows a report creator to upload files from local system into the report over the network. When uploading the image file, an…

  • CVE-2023-41108HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.01

    TEF portal 2023-07-17 is vulnerable to authenticated remote code execution.

  • CVE-2023-41638HigAug 31, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-4243HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to execute…

  • CVE-2023-36299HigAug 3, 2023
    risk 0.57cvss 8.8epss 0.02

    A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php.

  • CVE-2023-36298HigAug 3, 2023
    risk 0.57cvss 8.8epss 0.02

    DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE).

  • CVE-2022-28863HigJul 24, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the…

  • CVE-2020-22159HigJul 18, 2023
    risk 0.57cvss 8.8epss 0.01

    EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files.

  • CVE-2023-3342CriJul 13, 2023
    risk 0.57cvss 9.9epss 0.02

    The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible for authenticated…