VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 97 of 216
  • CVE-2022-2356HigAug 8, 2022
    risk 0.57cvss 8.8epss 0.01

    The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.

  • CVE-2022-34549HigJul 27, 2022
    risk 0.57cvss 8.8epss 0.01

    Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to escalate privileges and execute arbitrary commands via a crafted file.

  • CVE-2022-34971HigJul 27, 2022
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-34115CriJul 22, 2022
    risk 0.57cvss 9.8epss 0.01

    DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.

  • CVE-2022-24688HigJul 18, 2022
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and consequently Remote Code Execution) via PDF upload with PHP content and a .php extension. The attacker must hijack or obtain privileged user access to the…

  • CVE-2022-32119HigJul 15, 2022
    risk 0.57cvss 8.8epss 0.02

    Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php.

  • CVE-2021-36461HigJul 15, 2022
    risk 0.57cvss 8.8epss 0.01

    An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.

  • CVE-2022-32114HigJul 13, 2022
    risk 0.57cvss 8.8epss 0.02

    An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Media Library "Create (upload)" permission is supposed to be…

  • CVE-2015-1784HigJul 7, 2022
    risk 0.57cvss 8.8epss 0.02

    In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing…

  • CVE-2021-45982HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.

  • CVE-2022-30822HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file.

  • CVE-2022-30821HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file.

  • CVE-2022-30820HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file.

  • CVE-2022-30819HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file.

  • CVE-2022-29725HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-29624HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-29622CriMay 16, 2022
    risk 0.57cvss 9.8epss 0.03

    An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also,…

  • CVE-2022-29451HigApr 29, 2022
    risk 0.57cvss 8.8epss 0.01

    Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory.

  • CVE-2022-28528HigApr 26, 2022
    risk 0.57cvss 8.8epss 0.01

    bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.

  • CVE-2022-28525HigApr 26, 2022
    risk 0.57cvss 8.8epss 0.01

    ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1.