CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,316)
page 92 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-44061 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2023 | File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary code via the upload function in the edit profile component. | ||
| CVE-2023-43321 | Hig | 0.57 | 8.8 | 0.01 | Oct 4, 2023 | File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbitrary code via the wget function in the /sbin/cloudadmin.sh component. | ||
| CVE-2023-4097 | Hig | 0.57 | 8.8 | 0.01 | Oct 3, 2023 | The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attacker to log into the application with a valid username. | ||
| CVE-2023-5227 | Cri | 0.57 | 9.8 | 0.01 | Sep 30, 2023 | Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8. | ||
| CVE-2023-43740 | Hig | 0.57 | 8.8 | 0.01 | Sep 28, 2023 | Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application. | ||
| CVE-2023-43226 | Hig | 0.57 | 8.8 | 0.01 | Sep 28, 2023 | An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2023-42335 | — | Hig | 0.57 | 8.8 | 0.01 | Sep 20, 2023 | Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the add attachment function in the New Expense component. | |
| CVE-2023-42331 | Hig | 0.57 | 8.8 | 0.01 | Sep 20, 2023 | A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component. | ||
| CVE-2023-38887 | Hig | 0.57 | 8.8 | 0.01 | Sep 20, 2023 | File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions. | ||
| CVE-2023-36319 | Hig | 0.57 | 8.8 | 0.02 | Sep 20, 2023 | File Upload vulnerability in Openupload Stable v.0.4.3 allows a remote attacker to execute arbitrary code via the action parameter of the compress-inc.php file. | ||
| CVE-2023-42180 | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2023 | An arbitrary file upload vulnerability in the /user/upload component of lenosp 1.0-1.2.0 allows attackers to execute html code via a crafted JPG file. | ||
| CVE-2023-42472 | Hig | 0.57 | 8.7 | 0.01 | Sep 12, 2023 | Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows a report creator to upload files from local system into the report over the network. When uploading the image file, an… | ||
| CVE-2023-41108 | Hig | 0.57 | 8.8 | 0.01 | Sep 5, 2023 | TEF portal 2023-07-17 is vulnerable to authenticated remote code execution. | ||
| CVE-2023-41638 | Hig | 0.57 | 8.8 | 0.01 | Aug 31, 2023 | An arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2023-4243 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to execute… | ||
| CVE-2023-36299 | Hig | 0.57 | 8.8 | 0.02 | Aug 3, 2023 | A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php. | ||
| CVE-2023-36298 | Hig | 0.57 | 8.8 | 0.02 | Aug 3, 2023 | DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE). | ||
| CVE-2022-28863 | Hig | 0.57 | 8.8 | 0.01 | Jul 24, 2023 | An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the… | ||
| CVE-2020-22159 | Hig | 0.57 | 8.8 | 0.01 | Jul 18, 2023 | EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files. | ||
| CVE-2023-3342 | Cri | 0.57 | 9.9 | 0.02 | Jul 13, 2023 | The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible for authenticated… |
- risk 0.57cvss 8.8epss 0.01
File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary code via the upload function in the edit profile component.
- risk 0.57cvss 8.8epss 0.01
File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbitrary code via the wget function in the /sbin/cloudadmin.sh component.
- risk 0.57cvss 8.8epss 0.01
The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attacker to log into the application with a valid username.
- risk 0.57cvss 9.8epss 0.01
Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
- risk 0.57cvss 8.8epss 0.01
Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.57cvss 8.8epss 0.01
Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the add attachment function in the New Expense component.
- risk 0.57cvss 8.8epss 0.01
A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component.
- risk 0.57cvss 8.8epss 0.01
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
- risk 0.57cvss 8.8epss 0.02
File Upload vulnerability in Openupload Stable v.0.4.3 allows a remote attacker to execute arbitrary code via the action parameter of the compress-inc.php file.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in the /user/upload component of lenosp 1.0-1.2.0 allows attackers to execute html code via a crafted JPG file.
- risk 0.57cvss 8.7epss 0.01
Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows a report creator to upload files from local system into the report over the network. When uploading the image file, an…
- risk 0.57cvss 8.8epss 0.01
TEF portal 2023-07-17 is vulnerable to authenticated remote code execution.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.57cvss 8.8epss 0.01
The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to execute…
- risk 0.57cvss 8.8epss 0.02
A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php.
- risk 0.57cvss 8.8epss 0.02
DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE).
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the…
- risk 0.57cvss 8.8epss 0.01
EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files.
- risk 0.57cvss 9.9epss 0.02
The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible for authenticated…