CWE-434
4,365 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CVEs (4,365)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potential...Show more |
2Microfocus Netiq2Edirectory EdirectoryNov 21, 2024 Mar 2, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server. |
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to b...Show more |
In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If you have implemented a Settings Tray form...Show more |
1Christianwebministries 1Proclaim Jun 17, 2026 Feb 22, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action. |
In Bravo Tejari Procurement Portal, uploaded files are not properly validated by the application either on the client or the server side. An attacker can take advantage of this vulnerability and upload malicious executab...Show more |
1Hp 1Version Control Repository Manager Nov 21, 2024 Feb 15, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A remote malicious file upload vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6. |
1Ibm 2Maximo Asset Management Maximo Asset Management EssentialsNov 21, 2024 Feb 14, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 129106. |
1Schneider Electric 1Struxureon Gateway Nov 21, 2024 Feb 12, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains carefully crafted metadata allows for the file to be uploaded to any direct...Show more |
1Schools Alert Management Script Project 1Schools Alert Management Script Jun 17, 2026 Feb 12, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script 2.0.2 via a profile picture. |
Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request. |
In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution. |
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload. |
A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts NetIQ Access Manager versions 4.3 and 4.4 as well as the Administrative c...Show more |
An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, it is possible to upload a file on a filesystem with root privileges: th...Show more |
1Siemens 5Pxc00/50/100/200 E.d Firmware Pxc00/64/128 U FirmwarePxc001 E.d Firmware+2 moreNov 21, 2024 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability has been identified in Desigo PXC00-E.D V4.10 (All versions < V4.10.111), Desigo PXC00-E.D V5.00 (All versions < V5.0.171), Desigo PXC00-E.D V5.10 (All versions < V5.10.69), Desigo PXC00-E.D V6.00 (All ve...Show more |
2Minecraft Servers List Lite Project Premium Minecraft Servers List Project2Minecraft Servers List Lite Premium Minecraft Servers ListJun 17, 2026 Jan 23, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does not sanitize input before saving database connection information in connect.php, which might allow rem...Show more |
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not. |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability...Show more |
1Barni 1Master Ip Camera01 Firmware Jun 17, 2026 Jan 16, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi. |