CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,316)
page 97 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-2356 | Hig | 0.57 | 8.8 | 0.01 | Aug 8, 2022 | The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded. | ||
| CVE-2022-34549 | Hig | 0.57 | 8.8 | 0.01 | Jul 27, 2022 | Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to escalate privileges and execute arbitrary commands via a crafted file. | ||
| CVE-2022-34971 | Hig | 0.57 | 8.8 | 0.01 | Jul 27, 2022 | An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-34115 | Cri | 0.57 | 9.8 | 0.01 | Jul 22, 2022 | DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId. | ||
| CVE-2022-24688 | Hig | 0.57 | 8.8 | 0.03 | Jul 18, 2022 | An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and consequently Remote Code Execution) via PDF upload with PHP content and a .php extension. The attacker must hijack or obtain privileged user access to the… | ||
| CVE-2022-32119 | Hig | 0.57 | 8.8 | 0.02 | Jul 15, 2022 | Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php. | ||
| CVE-2021-36461 | Hig | 0.57 | 8.8 | 0.01 | Jul 15, 2022 | An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini. | ||
| CVE-2022-32114 | Hig | 0.57 | 8.8 | 0.02 | Jul 13, 2022 | An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Media Library "Create (upload)" permission is supposed to be… | ||
| CVE-2015-1784 | Hig | 0.57 | 8.8 | 0.02 | Jul 7, 2022 | In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing… | ||
| CVE-2021-45982 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user. | ||
| CVE-2022-30822 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file. | ||
| CVE-2022-30821 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file. | ||
| CVE-2022-30820 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file. | ||
| CVE-2022-30819 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file. | ||
| CVE-2022-29725 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-29624 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-29622 | Cri | 0.57 | 9.8 | 0.03 | May 16, 2022 | An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also,… | ||
| CVE-2022-29451 | Hig | 0.57 | 8.8 | 0.01 | Apr 29, 2022 | Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory. | ||
| CVE-2022-28528 | Hig | 0.57 | 8.8 | 0.01 | Apr 26, 2022 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit. | ||
| CVE-2022-28525 | Hig | 0.57 | 8.8 | 0.01 | Apr 26, 2022 | ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1. |
- risk 0.57cvss 8.8epss 0.01
The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.
- risk 0.57cvss 8.8epss 0.01
Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to escalate privileges and execute arbitrary commands via a crafted file.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.57cvss 9.8epss 0.01
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
- risk 0.57cvss 8.8epss 0.03
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and consequently Remote Code Execution) via PDF upload with PHP content and a .php extension. The attacker must hijack or obtain privileged user access to the…
- risk 0.57cvss 8.8epss 0.02
Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php.
- risk 0.57cvss 8.8epss 0.01
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.
- risk 0.57cvss 8.8epss 0.02
An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Media Library "Create (upload)" permission is supposed to be…
- risk 0.57cvss 8.8epss 0.02
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing…
- risk 0.57cvss 8.8epss 0.01
NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.
- risk 0.57cvss 8.8epss 0.01
In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file.
- risk 0.57cvss 8.8epss 0.01
In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file.
- risk 0.57cvss 8.8epss 0.01
In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file.
- risk 0.57cvss 8.8epss 0.01
In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.57cvss 9.8epss 0.03
An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also,…
- risk 0.57cvss 8.8epss 0.01
Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory.
- risk 0.57cvss 8.8epss 0.01
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.
- risk 0.57cvss 8.8epss 0.01
ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1.