← Back
CWE-434

4,365 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

JSON object

Loading...

CVEs (4,365)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hanwhasecurity
1Web Viewer
May 13, 2026
Nov 6, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrary PHP code via a file...Show more
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrary PHP code via a filename with a .php extension, which is then accessed via a direct request to the file in the upload/ directory. To authenticate for this attack, one can obtain web-interface credentials in cleartext by leveraging the existing Local File Read Vulnerability referenced as CVE-2015-8279, which allows remote attackers to read the web-interface credentials via a request for the cslog_export.php?path=/root/php_modules/lighttpd/sbin/userpw URI.Show less
1Joyent
1Triton Datacenter
May 13, 2026
Oct 31, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Joyent Smart Data Center prior to agentsshar@1.0.0-release-20160901-20160901T051624Z-g3fd5adf (e469cf49-4de3-4658-8419-a...Show more
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Joyent Smart Data Center prior to agentsshar@1.0.0-release-20160901-20160901T051624Z-g3fd5adf (e469cf49-4de3-4658-8419-ab42837916ad). An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the docker API. The process does not properly validate user-supplied data which can allow for the upload of arbitrary files. An attacker can leverage this vulnerability to execute arbitrary code under the context of root. Was ZDI-CAN-3853.Show less
1Savsofteproducts
1Phpinventory
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
1Istock Management System Project
1Istock Management System
May 13, 2026
Oct 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
1Ingenious School Management System Project
1Ingenious School Management System
May 13, 2026
Oct 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.
1Labwiki Project
1Labwiki
May 13, 2026
Oct 23, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP files via a PHP file with a .gif extension in the userfile parameter.
1Osticket
1Osticket
May 13, 2026
Oct 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php r...Show more
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.Show less
1X2engine
1X2crm
May 13, 2026
Oct 17, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in X2Engine X2CRM before 4.0 allows remote attackers to execute arbitrary code by u...Show more
Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in X2Engine X2CRM before 4.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.Show less
1Berta
1Berta Cms
May 13, 2026
Oct 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in...Show more
Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.Show less
1Octobercms
1October
May 13, 2026
Oct 5, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.
6Apache
CanonicalDebian+3 more
59Active Iq Unified Manager
Agile PlmAgile Product Lifecycle Management+56 more
Aug 25, 2026
Oct 4, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to fal...Show more
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.Show less
1Phpcollab
1Phpcollab
May 13, 2026
Oct 3, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing...Show more
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/.Show less
1Pivotx
1Pivotx
May 13, 2026
Oct 2, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file.
1Hp
1Bsm Platform Application Performance Management System Health
May 13, 2026
Sep 30, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows users to upload unrestricted files.
1Dasinfomedia
1Annual Maintenance Contract Management System
May 13, 2026
Sep 28, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.
1Teamworktec
1Ticketplus
May 13, 2026
Sep 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
1Teamworktec
1Photo Fusion
May 13, 2026
Sep 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
1Teamworktec
1Job Links
May 13, 2026
Sep 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
1Manageengine
1Desktop Central
May 13, 2026
Sep 28, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.
1Claydip
1Airbnb Clone
May 13, 2026
Sep 26, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file w...Show more
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/profile.Show less