CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,316)
page 94 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-31576 | Hig | 0.57 | 8.8 | 0.01 | May 16, 2023 | An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file. | ||
| CVE-2023-29657 | Hig | 0.57 | 8.8 | 0.01 | May 12, 2023 | eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary code executions. | ||
| CVE-2021-34076 | Hig | 0.57 | 8.8 | 0.01 | May 11, 2023 | File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload. | ||
| CVE-2023-29930 | Hig | 0.57 | 8.8 | 0.02 | May 10, 2023 | An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login crednetials to the TFTP server configuration page. | ||
| CVE-2023-28128 | Hig | 0.57 | 7.2 | 0.85 | May 9, 2023 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. | ||
| CVE-2023-24507 | Hig | 0.57 | 8.8 | 0.01 | May 8, 2023 | AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecified request. | ||
| CVE-2020-22755 | Hig | 0.57 | 8.8 | 0.01 | May 8, 2023 | File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943. | ||
| CVE-2022-45802 | Cri | 0.57 | 9.8 | 0.01 | May 1, 2023 | Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark… | ||
| CVE-2023-24269 | Hig | 0.57 | 8.8 | 0.01 | Apr 28, 2023 | An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file. | ||
| CVE-2023-30266 | Hig | 0.57 | 8.8 | 0.01 | Apr 26, 2023 | CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. | ||
| CVE-2023-27755 | Hig | 0.57 | 8.8 | 0.01 | Apr 17, 2023 | go-bbs v1 was discovered to contain an arbitrary file download vulnerability via the component /api/v1/download. | ||
| CVE-2023-29627 | Hig | 0.57 | 8.8 | 0.01 | Apr 14, 2023 | Online Pizza Ordering v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server. | ||
| CVE-2023-29625 | Hig | 0.57 | 8.8 | 0.01 | Apr 14, 2023 | Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server. | ||
| CVE-2023-29621 | Hig | 0.57 | 8.8 | 0.01 | Apr 14, 2023 | Purchase Order Management v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server. | ||
| CVE-2023-27179 | Hig | 0.57 | 7.5 | 0.61 | Apr 11, 2023 | GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php. | ||
| CVE-2023-1406 | Hig | 0.57 | 8.8 | 0.02 | Apr 10, 2023 | The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability. | ||
| CVE-2023-0265 | Hig | 0.57 | 8.8 | 0.02 | Apr 4, 2023 | Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers. | ||
| CVE-2023-27246 | Hig | 0.57 | 8.8 | 0.01 | Mar 28, 2023 | An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file. | ||
| CVE-2023-25655 | Cri | 0.57 | 9.8 | 0.01 | Mar 23, 2023 | baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch. | ||
| CVE-2023-25654 | Cri | 0.57 | 9.8 | 0.02 | Mar 23, 2023 | baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a patch. |
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.
- risk 0.57cvss 8.8epss 0.01
eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary code executions.
- risk 0.57cvss 8.8epss 0.01
File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload.
- risk 0.57cvss 8.8epss 0.02
An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login crednetials to the TFTP server configuration page.
- risk 0.57cvss 7.2epss 0.85
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.
- risk 0.57cvss 8.8epss 0.01
AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecified request.
- risk 0.57cvss 8.8epss 0.01
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.
- risk 0.57cvss 9.8epss 0.01
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark…
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.
- risk 0.57cvss 8.8epss 0.01
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type.
- risk 0.57cvss 8.8epss 0.01
go-bbs v1 was discovered to contain an arbitrary file download vulnerability via the component /api/v1/download.
- risk 0.57cvss 8.8epss 0.01
Online Pizza Ordering v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.
- risk 0.57cvss 8.8epss 0.01
Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.
- risk 0.57cvss 8.8epss 0.01
Purchase Order Management v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.
- risk 0.57cvss 7.5epss 0.61
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.
- risk 0.57cvss 8.8epss 0.02
The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.
- risk 0.57cvss 8.8epss 0.02
Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file.
- risk 0.57cvss 9.8epss 0.01
baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch.
- risk 0.57cvss 9.8epss 0.02
baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a patch.