VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 98 of 216
  • CVE-2021-4225HigApr 25, 2022
    risk 0.57cvss 8.8epss 0.02

    The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file…

  • CVE-2022-28053HigApr 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-28440HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.02

    An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2021-4096HigApr 19, 2022
    risk 0.57cvss 8.8epss 0.01

    The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versions up to, and including,…

  • CVE-2022-27352HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.03

    Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27346HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.03

    Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27064HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.03

    Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2021-43430HigApr 7, 2022
    risk 0.57cvss 8.8epss 0.01

    An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files.

  • CVE-2022-26627HigApr 7, 2022
    risk 0.57cvss 8.8epss 0.01

    Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrary code via a crafted HTML file.

  • CVE-2022-26605HigApr 6, 2022
    risk 0.57cvss 8.8epss 0.01

    eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality.

  • CVE-2022-26630HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\db.php.

  • CVE-2022-28062HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.02

    Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and execute arbitrary code.

  • CVE-2022-27435HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.02

    An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.

  • CVE-2021-34257HigMar 31, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.

  • CVE-2022-0499HigMar 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.

  • CVE-2022-23346HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.01

    BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.

  • CVE-2022-0687HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.01

    The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

  • CVE-2021-43970HigMar 10, 2022
    risk 0.57cvss 8.8epss 0.02

    An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within…

  • CVE-2022-24254HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.03

    An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.

  • CVE-2022-24253HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.