CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,316)
page 98 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-4225 | Hig | 0.57 | 8.8 | 0.02 | Apr 25, 2022 | The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file… | ||
| CVE-2022-28053 | Hig | 0.57 | 8.8 | 0.01 | Apr 25, 2022 | Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-28440 | Hig | 0.57 | 8.8 | 0.02 | Apr 21, 2022 | An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2021-4096 | Hig | 0.57 | 8.8 | 0.01 | Apr 19, 2022 | The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versions up to, and including,… | ||
| CVE-2022-27352 | Hig | 0.57 | 8.8 | 0.03 | Apr 8, 2022 | Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-27346 | Hig | 0.57 | 8.8 | 0.03 | Apr 8, 2022 | Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-27064 | Hig | 0.57 | 8.8 | 0.03 | Apr 8, 2022 | Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2021-43430 | Hig | 0.57 | 8.8 | 0.01 | Apr 7, 2022 | An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files. | ||
| CVE-2022-26627 | Hig | 0.57 | 8.8 | 0.01 | Apr 7, 2022 | Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrary code via a crafted HTML file. | ||
| CVE-2022-26605 | Hig | 0.57 | 8.8 | 0.01 | Apr 6, 2022 | eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality. | ||
| CVE-2022-26630 | Hig | 0.57 | 8.8 | 0.01 | Apr 5, 2022 | Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\db.php. | ||
| CVE-2022-28062 | Hig | 0.57 | 8.8 | 0.02 | Apr 4, 2022 | Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and execute arbitrary code. | ||
| CVE-2022-27435 | Hig | 0.57 | 8.8 | 0.02 | Apr 4, 2022 | An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component. | ||
| CVE-2021-34257 | Hig | 0.57 | 8.8 | 0.02 | Mar 31, 2022 | Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image. | ||
| CVE-2022-0499 | Hig | 0.57 | 8.8 | 0.01 | Mar 28, 2022 | The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones. | ||
| CVE-2022-23346 | Hig | 0.57 | 8.8 | 0.01 | Mar 21, 2022 | BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues. | ||
| CVE-2022-0687 | Hig | 0.57 | 8.8 | 0.01 | Mar 21, 2022 | The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role. | ||
| CVE-2021-43970 | Hig | 0.57 | 8.8 | 0.02 | Mar 10, 2022 | An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within… | ||
| CVE-2022-24254 | Hig | 0.57 | 8.8 | 0.03 | Mar 1, 2022 | An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file. | ||
| CVE-2022-24253 | Hig | 0.57 | 8.8 | 0.01 | Mar 1, 2022 | Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet. |
- risk 0.57cvss 8.8epss 0.02
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file…
- risk 0.57cvss 8.8epss 0.01
Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.57cvss 8.8epss 0.02
An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.57cvss 8.8epss 0.01
The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versions up to, and including,…
- risk 0.57cvss 8.8epss 0.03
Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.57cvss 8.8epss 0.03
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.57cvss 8.8epss 0.03
Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.57cvss 8.8epss 0.01
An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files.
- risk 0.57cvss 8.8epss 0.01
Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrary code via a crafted HTML file.
- risk 0.57cvss 8.8epss 0.01
eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality.
- risk 0.57cvss 8.8epss 0.01
Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\db.php.
- risk 0.57cvss 8.8epss 0.02
Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and execute arbitrary code.
- risk 0.57cvss 8.8epss 0.02
An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.
- risk 0.57cvss 8.8epss 0.02
Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.
- risk 0.57cvss 8.8epss 0.01
The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.
- risk 0.57cvss 8.8epss 0.01
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.
- risk 0.57cvss 8.8epss 0.01
The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.
- risk 0.57cvss 8.8epss 0.02
An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within…
- risk 0.57cvss 8.8epss 0.03
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.
- risk 0.57cvss 8.8epss 0.01
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.