CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,557 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 29 of 92
- CVE-2019-13082CRITICALCVSS 9.8EG 9.82019-06-30
Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursiv…
- CVE-2019-7838CRITICALCVSS 9.8EG 9.82019-06-12
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2019-9642CRITICALCVSS 9.8EG 9.82019-06-05
An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourth line of a .php file, as demonstrated by a PoC.php created…
- CVE-2019-11185CRITICALCVSS 9.8EG 9.82019-06-03
The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted execut…
- CVE-2019-12377CRITICALCVSS 9.8EG 9.82019-06-03
A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution.
- CVE-2019-7816CRITICALCVSS 9.8EG 9.82019-05-24
ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2016-10752CRITICALCVSS 9.8EG 9.82019-05-24
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename.
- CVE-2019-12150CRITICALCVSS 9.8EG 9.82019-05-24
Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under …
- CVE-2019-11887CRITICALCVSS 9.8EG 9.82019-05-17
SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution.
- CVE-2019-9951CRITICALCVSS 9.8EG 9.82019-04-24
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upl…
- CVE-2019-11344CRITICALCVSS 9.8EG 9.82019-04-19
data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked.
- CVE-2019-11223CRITICALCVSS 9.8EG 9.82019-04-18
An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
- CVE-2019-3940CRITICALCVSS 9.8EG 9.82019-04-09
Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code.
- CVE-2019-10647CRITICALCVSS 9.8EG 9.82019-03-30
ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of a lack of inc/zzz_file.php restrictions. For example, sourc…
- CVE-2019-10276CRITICALCVSS 9.8EG 9.82019-03-29
Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the image/jpeg content type.
- CVE-2018-20526CRITICALCVSS 9.8EG 9.82019-03-21
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
- CVE-2018-19514CRITICALCVSS 9.8EG 9.82019-03-21
In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. Exploitation requires authentication bypass to access administrative functions of the site to upload a crafted CSV file…
- CVE-2019-9825CRITICALCVSS 9.8EG 9.82019-03-14
FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Index to modify the set of allowable file extensions, as demonstrated by adding php to the default jpg,gif,png,jpeg setting…
- CVE-2019-9623CRITICALCVSS 9.8EG 9.82019-03-07
Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.
- CVE-2019-0259CRITICALCVSS 9.8EG 9.82019-02-15
SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation.
- CVE-2019-7684CRITICALCVSS 9.8EG 9.82019-02-09
inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.common.controller.VideoUploadController#gok4 (com/inxedu/os/common/controller/VideoUploadContr…
- CVE-2019-6139CRITICALCVSS 9.8EG 9.82019-02-07
Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. Successful exploitation of this vulnerability may lead to remote code execution. To fix this vulnerability, upgrade to …
- CVE-2018-5204CRITICALCVSS 9.8EG 9.82018-12-28
ML Report version Between 2.00.000.0000 and 2.18.628.5980 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. this can be leveraged for cod…
- CVE-2018-7836CRITICALCVSS 9.8EG 9.82018-12-24
An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.
- CVE-2018-19692CRITICALCVSS 9.8EG 9.82018-11-29
An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploading a .php file with the image/jpeg content type.
- CVE-2018-17936CRITICALCVSS 9.8EG 9.82018-11-27
NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote code execution.
- CVE-2018-9209CRITICALCVSS 9.8EG 9.82018-11-19
Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2
- CVE-2018-9207CRITICALCVSS 9.8EG 9.82018-11-19
Arbitrary file upload in jQuery Upload File <= 4.0.2
- CVE-2018-19355CRITICALCVSS 9.8EG 9.82018-11-19
modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equa…
- CVE-2018-18793CRITICALCVSS 9.8EG 9.82018-11-16
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
- CVE-2018-19126CRITICALCVSS 9.8EG 9.82018-11-09
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.
- CVE-2018-9208CRITICALCVSS 9.8EG 9.82018-11-05
Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta
- CVE-2018-18934CRITICALCVSS 9.8EG 9.82018-11-05
An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a ZIP file containing arbitrary PHP code (that is extracted an…
- CVE-2018-18888CRITICALCVSS 9.8EG 9.82018-11-01
An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files because the file extension is not properly checked and uploaded files are not properly renam…
- CVE-2018-18874CRITICALCVSS 9.8EG 9.82018-10-31
nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Content-Type: application/octet-stream" to the index.php?action=file_manager_upload URI.
- CVE-2018-18830CRITICALCVSS 9.8EG 9.82018-10-30
An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an …
- CVE-2018-18752CRITICALCVSS 9.8EG 9.82018-10-29
Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo parameter.
- CVE-2018-18475CRITICALCVSS 9.8EG 9.82018-10-23
Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.
- CVE-2018-9206CRITICALCVSS 9.8EG 9.82018-10-11
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
- CVE-2018-17440CRITICALCVSS 9.8EG 9.82018-10-08
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). Taking advantage of this, a remote unauthenticated…
- CVE-2015-9271CRITICALCVSS 9.8EG 9.82018-10-04
The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrat…
- CVE-2018-17573CRITICALCVSS 9.8EG 9.82018-09-28
The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configuration of FCKeditor under fckeditor/editor/filemanager/browser/default/browser.html, fckeditor/editor/filemanager/conne…
- CVE-2018-16287CRITICALCVSS 9.8EG 9.82018-09-14
LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.
- CVE-2018-16974CRITICALCVSS 9.8EG 9.82018-09-12
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /filemanager/api/rm/.htaccess to remove the .htaccess file, and then using a filename that ends i…
- CVE-2018-16731CRITICALCVSS 9.8EG 9.82018-09-08
CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.
- CVE-2018-0645CRITICALCVSS 9.8EG 9.82018-09-07
MTAppjQuery 1.8.1 and earlier allows remote PHP code execution via unspecified vectors.
- CVE-2018-16370CRITICALCVSS 9.8EG 9.82018-09-03
In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a ZIP archive.
- CVE-2018-16352CRITICALCVSS 9.8EG 9.82018-09-02
There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a .png file when the image/png content type is used.
- CVE-2018-15882CRITICALCVSS 9.8EG 9.82018-08-29
An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the upload filter.
- CVE-2015-9263CRITICALCVSS 9.8EG 9.82018-08-27
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →