CWE-434
4,365 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CVEs (4,365)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrary PHP code via a file...Show more |
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Joyent Smart Data Center prior to agentsshar@1.0.0-release-20160901-20160901T051624Z-g3fd5adf (e469cf49-4de3-4658-8419-a...Show more |
1Savsofteproducts 1Phpinventory May 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. |
1Istock Management System Project 1Istock Management System May 13, 2026 Oct 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 iStock Management System 1.0 allows Arbitrary File Upload via user/profile. |
1Ingenious School Management System Project 1Ingenious School Management System May 13, 2026 Oct 29, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file. |
edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP files via a PHP file with a .gif extension in the userfile parameter. |
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php r...Show more |
Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in X2Engine X2CRM before 4.0 allows remote attackers to execute arbitrary code by u...Show more |
Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in...Show more |
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server. |
6Apache CanonicalDebian+3 more59Active Iq Unified Manager Agile PlmAgile Product Lifecycle Management+56 moreAug 25, 2026 Oct 4, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to fal...Show more |
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing...Show more |
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file. |
1Hp 1Bsm Platform Application Performance Management System Health May 13, 2026 Sep 30, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows users to upload unrestricted files. |
1Dasinfomedia 1Annual Maintenance Contract Management System May 13, 2026 Sep 28, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling. |
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile. |
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover. |
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange. |
1Manageengine 1Desktop Central May 13, 2026 Sep 28, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter. |
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file w...Show more |