CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,557 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 28 of 92
- CVE-2019-20451CRITICALCVSS 9.8EG 9.82020-02-10
The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and requesting /REBOOTSYSTEM or /RESTARTVNC. (Authentication is required but an XML file containin…
- CVE-2014-8739CRITICALCVSS 9.8EG 9.82020-02-08
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and b…
- CVE-2020-6754CRITICALCVSS 9.8EG 9.82020-02-05
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, att…
- CVE-2014-2025CRITICALCVSS 9.8EG 9.82020-01-31
Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploadin…
- CVE-2020-8440CRITICALCVSS 9.8EG 9.82020-01-31
controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume.
- CVE-2013-2748CRITICALCVSS 9.8EG 9.82020-01-28
Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.
- CVE-2013-7390CRITICALCVSS 9.8EG 9.82020-01-27
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it v…
- CVE-2012-6649CRITICALCVSS 9.8EG 9.82020-01-23
WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.
- CVE-2012-5190CRITICALCVSS 9.8EG 9.82020-01-21
Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability
- CVE-2012-2226CRITICALCVSS 9.8EG 9.82020-01-09
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.
- CVE-2014-3448CRITICALCVSS 9.8EG 9.82020-01-09
BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload
- CVE-2014-8516CRITICALCVSS 9.8EG 9.82020-01-03
Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.
- CVE-2014-8337CRITICALCVSS 9.8EG 9.82020-01-03
Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it v…
- CVE-2019-8293CRITICALCVSS 9.8EG 9.82019-12-23
Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution.
- CVE-2019-19634CRITICALCVSS 9.8EG 9.82019-12-17
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.
- CVE-2019-18313CRITICALCVSS 9.8EG 9.82019-12-12
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could gain remote code execution by sending specifically crafted objects to one of the RPC servi…
- CVE-2019-15936CRITICALCVSS 9.8EG 9.82019-12-12
Intesync Solismed 3.3sp allows Insecure File Upload.
- CVE-2019-19595CRITICALCVSS 9.8EG 9.82019-12-05
reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.
- CVE-2019-19594CRITICALCVSS 9.8EG 9.82019-12-05
reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.
- CVE-2019-19576CRITICALCVSS 9.8EG 9.82019-12-04
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
- CVE-2019-12409CRITICALCVSS 9.8EG 9.82019-11-18
The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the af…
- CVE-2019-12271CRITICALCVSS 9.8EG 9.82019-11-18
Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the server side.
- CVE-2019-18952CRITICALCVSS 9.8EG 9.82019-11-13
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.
- CVE-2019-12719CRITICALCVSS 9.8EG 9.82019-11-12
An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an incorrect access control vulnerability that can allow an unauthenticated user to upload files via a modified authority par…
- CVE-2011-1134CRITICALCVSS 9.8EG 9.82019-11-05
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.
- CVE-2019-14451CRITICALCVSS 9.8EG 9.82019-10-25
RepetierServer.exe in Repetier-Server 0.8 through 0.91 does not properly validate the XML data structure provided when uploading a new printer configuration. When this is combined with CVE-2019-14450, an attacker can upload an "external co…
- CVE-2015-9499CRITICALCVSS 9.8EG 9.82019-10-22
The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
- CVE-2019-16700CRITICALCVSS 9.8EG 9.82019-10-16
The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below, this results in Remote Code Execution. In versions later than 1.2.2, this …
- CVE-2015-9479CRITICALCVSS 9.8EG 9.82019-10-10
The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.
- CVE-2015-9471CRITICALCVSS 9.8EG 9.82019-10-10
The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
- CVE-2018-21024CRITICALCVSS 9.8EG 9.82019-10-08
licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.
- CVE-2019-15751CRITICALCVSS 9.8EG 9.82019-10-07
An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM file with an executable extension. This allows an unauthenticated attacker to upload a malicious fil…
- CVE-2019-15748CRITICALCVSS 9.8EG 9.82019-10-07
SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages. An unauthenticated attacker could use the upload and import functionality to import a malicious SCORM packa…
- CVE-2016-10995CRITICALCVSS 9.8EG 9.82019-09-18
The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php.
- CVE-2019-15131CRITICALCVSS 9.8EG 9.82019-09-17
In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to be uploaded to Code42 servers and executed. This vulnerability could allow an attacker to create d…
- CVE-2016-10955CRITICALCVSS 9.8EG 9.82019-09-13
The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.
- CVE-2016-10954CRITICALCVSS 9.8EG 9.82019-09-13
The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.
- CVE-2019-16192CRITICALCVSS 9.8EG 9.82019-09-09
upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbitrary PHP code through module management files, as demonstrated by a .php file in a ZIP archive.
- CVE-2019-13187CRITICALCVSS 9.8EG 9.82019-09-05
The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php.
- CVE-2019-13976CRITICALCVSS 9.8EG 9.82019-09-04
eGain Chat 15.0.3 allows unrestricted file upload.
- CVE-2019-15524CRITICALCVSS 9.8EG 9.82019-08-26
CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote code execution by visiting a photo/upload/2019/ URI.
- CVE-2019-11031CRITICALCVSS 9.8EG 9.82019-08-22
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, and then execute these files with SYSTEM privileges.
- CVE-2019-15130CRITICALCVSS 9.8EG 9.82019-08-18
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a crafted recruitment_online/personalData/act_personaltab.cfm mult…
- CVE-2019-15091CRITICALCVSS 9.8EG 9.82019-08-16
filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.
- CVE-2019-13973CRITICALCVSS 9.8EG 9.82019-07-19
LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used.
- CVE-2019-1010062CRITICALCVSS 9.8EG 9.82019-07-16
PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type. The impact is: get webshell. The component is: data/inc/images.php line36. The attack vector is: modify the MIME TYPE on HTTP request to up…
- CVE-2019-12803CRITICALCVSS 9.8EG 9.82019-07-10
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell upload, an attacker can use the webshell t…
- CVE-2019-12971CRITICALCVSS 9.8EG 9.82019-07-05
BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type.
- CVE-2019-13294CRITICALCVSS 9.8EG 9.82019-07-04
AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.
- CVE-2019-7274CRITICALCVSS 9.8EG 9.82019-07-01
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →