VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 94 of 216
  • CVE-2023-31576HigMay 16, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.

  • CVE-2023-29657HigMay 12, 2023
    risk 0.57cvss 8.8epss 0.01

    eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary code executions.

  • CVE-2021-34076HigMay 11, 2023
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload.

  • CVE-2023-29930HigMay 10, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login crednetials to the TFTP server configuration page.

  • CVE-2023-28128HigMay 9, 2023
    risk 0.57cvss 7.2epss 0.85

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.

  • CVE-2023-24507HigMay 8, 2023
    risk 0.57cvss 8.8epss 0.01

    AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecified request.

  • CVE-2020-22755HigMay 8, 2023
    risk 0.57cvss 8.8epss 0.01

    File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.

  • CVE-2022-45802CriMay 1, 2023
    risk 0.57cvss 9.8epss 0.01

    Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark…

  • CVE-2023-24269HigApr 28, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.

  • CVE-2023-30266HigApr 26, 2023
    risk 0.57cvss 8.8epss 0.01

    CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type.

  • CVE-2023-27755HigApr 17, 2023
    risk 0.57cvss 8.8epss 0.01

    go-bbs v1 was discovered to contain an arbitrary file download vulnerability via the component /api/v1/download.

  • CVE-2023-29627HigApr 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Pizza Ordering v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.

  • CVE-2023-29625HigApr 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.

  • CVE-2023-29621HigApr 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Purchase Order Management v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.

  • CVE-2023-27179HigApr 11, 2023
    risk 0.57cvss 7.5epss 0.61

    GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.

  • CVE-2023-1406HigApr 10, 2023
    risk 0.57cvss 8.8epss 0.02

    The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.

  • CVE-2023-0265HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.02

    Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.

  • CVE-2023-27246HigMar 28, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file.

  • CVE-2023-25655CriMar 23, 2023
    risk 0.57cvss 9.8epss 0.01

    baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch.

  • CVE-2023-25654CriMar 23, 2023
    risk 0.57cvss 9.8epss 0.02

    baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a patch.