CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,316)
page 99 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24252 | Hig | 0.57 | 8.8 | 0.02 | Mar 1, 2022 | An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file. | ||
| CVE-2022-24251 | Hig | 0.57 | 8.8 | 0.01 | Mar 1, 2022 | Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function. | ||
| CVE-2022-25360 | Hig | 0.57 | 8.8 | 0.01 | Feb 24, 2022 | WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload files to arbitrary locations. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2. | ||
| CVE-2022-24676 | Hig | 0.57 | 8.8 | 0.01 | Feb 9, 2022 | update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive. | ||
| CVE-2022-24262 | Hig | 0.57 | 8.8 | 0.02 | Feb 4, 2022 | The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root. | ||
| CVE-2021-46097 | Hig | 0.57 | 8.8 | 0.02 | Jan 27, 2022 | Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log | ||
| CVE-2021-44123 | Hig | 0.57 | 8.8 | 0.02 | Jan 26, 2022 | SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it. | ||
| CVE-2021-46113 | Hig | 0.57 | 8.8 | 0.03 | Jan 25, 2022 | In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service. | ||
| CVE-2021-45808 | Hig | 0.57 | 8.8 | 0.01 | Jan 19, 2022 | jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server. | ||
| CVE-2021-33828 | Hig | 0.57 | 8.8 | 0.01 | Jan 15, 2022 | The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection. | ||
| CVE-2021-43973 | Hig | 0.57 | 8.8 | 0.02 | Jan 11, 2022 | An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitrary file via the file parameter in the HTTP POST body. A successful request returns the absolute, server-side filesystem path of… | ||
| CVE-2021-46076 | Hig | 0.57 | 8.8 | 0.03 | Jan 6, 2022 | Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints it leading to Code Execution. | ||
| CVE-2021-41870 | Hig | 0.57 | 8.8 | 0.01 | Dec 15, 2021 | An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type check and upload arbitrary .php files. | ||
| CVE-2021-36719 | Hig | 0.57 | 8.8 | 0.01 | Dec 8, 2021 | PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulnerable nicUpload.php file to upload a malicious file,Thus taking over the server and running remote code. | ||
| CVE-2021-42839 | Hig | 0.57 | 8.8 | 0.02 | Nov 15, 2021 | Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attackers can upload malicious script and execute arbitrary code to control the system or interrupt services. | ||
| CVE-2020-23572 | Hig | 0.57 | 8.8 | 0.01 | Nov 8, 2021 | BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file. | ||
| CVE-2021-31599 | Hig | 0.57 | 8.8 | 0.02 | Nov 8, 2021 | An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A reports (.prpt) file allows the inclusion of BeanShell scripts to ease the production of complex reports. An authenticated user can run arbitrary code. | ||
| CVE-2021-38847 | Hig | 0.57 | 8.8 | 0.01 | Nov 1, 2021 | S-Cart v6.4.1 and below was discovered to contain an arbitrary file upload vulnerability in the Editor module on the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted IMG file. | ||
| CVE-2021-41645 | Hig | 0.57 | 8.8 | 0.03 | Oct 29, 2021 | Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to inject arbitrary code via the image upload field. . | ||
| CVE-2021-37221 | Hig | 0.57 | 8.8 | 0.01 | Oct 27, 2021 | A file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update option & customer create option, which could let a remote malicious user upload an arbitrary php file. . |
- risk 0.57cvss 8.8epss 0.02
An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.
- risk 0.57cvss 8.8epss 0.01
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.
- risk 0.57cvss 8.8epss 0.01
WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload files to arbitrary locations. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
- risk 0.57cvss 8.8epss 0.01
update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.
- risk 0.57cvss 8.8epss 0.02
The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root.
- risk 0.57cvss 8.8epss 0.02
Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log
- risk 0.57cvss 8.8epss 0.02
SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.
- risk 0.57cvss 8.8epss 0.03
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.
- risk 0.57cvss 8.8epss 0.01
jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.
- risk 0.57cvss 8.8epss 0.01
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.
- risk 0.57cvss 8.8epss 0.02
An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitrary file via the file parameter in the HTTP POST body. A successful request returns the absolute, server-side filesystem path of…
- risk 0.57cvss 8.8epss 0.03
Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints it leading to Code Execution.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type check and upload arbitrary .php files.
- risk 0.57cvss 8.8epss 0.01
PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulnerable nicUpload.php file to upload a malicious file,Thus taking over the server and running remote code.
- risk 0.57cvss 8.8epss 0.02
Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attackers can upload malicious script and execute arbitrary code to control the system or interrupt services.
- risk 0.57cvss 8.8epss 0.01
BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A reports (.prpt) file allows the inclusion of BeanShell scripts to ease the production of complex reports. An authenticated user can run arbitrary code.
- risk 0.57cvss 8.8epss 0.01
S-Cart v6.4.1 and below was discovered to contain an arbitrary file upload vulnerability in the Editor module on the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted IMG file.
- risk 0.57cvss 8.8epss 0.03
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to inject arbitrary code via the image upload field. .
- risk 0.57cvss 8.8epss 0.01
A file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update option & customer create option, which could let a remote malicious user upload an arbitrary php file. .