CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,266 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 4 of 86
- CVE-2016-3088CRITICALCVSS 9.8EG 9.8⚠ KEV2016-06-01
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
- CVE-2016-5050CRITICALCVSS 9.8EG 9.82016-08-26
Unrestricted file upload vulnerability in chat/sendfile.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary code by uploading and requesting a .aspx file.
- CVE-2016-6104HIGHCVSS 7.2EG 7.22017-02-07
IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the vulnerable system.
- CVE-2016-6124HIGHCVSS 8.8EG 8.82017-02-01
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
- CVE-2016-6918CRITICALCVSS 9.8EG 9.82020-03-09
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (
- CVE-2016-7095CRITICALCVSS 9.8EG 9.82016-11-03
Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprotected folder, one allowing script execution.
- CVE-2016-7443CRITICALCVSS 9.8EG 9.82018-03-07
Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."
- CVE-2016-7452HIGHCVSS 7.5EG 7.52016-11-03
The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to upload a malicious file to any folder on the site via a cpi directory traversal.
- CVE-2016-7902HIGHCVSS 8.8EG 8.82017-01-04
Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by uploading a ZIP file containing a file wi…
- CVE-2016-8515HIGHCVSS 8.8EG 8.82018-02-15
A remote malicious file upload vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.
- CVE-2016-8921HIGHCVSS 8.8EG 8.82017-02-01
IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
- CVE-2016-8973MEDIUMCVSS 4.3EG 4.32017-03-20
IBM Rhapsody DM 4.0, 5.0 and 6.0 contains an undisclosed vulnerability that may allow an authenticated user to upload infected malicious files to the server. IBM Reference #: 1999960.
- CVE-2016-9186HIGHCVSS 8.8EG 8.82016-11-04
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing…
- CVE-2016-9187HIGHCVSS 8.8EG 8.82016-11-04
Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing i…
- CVE-2016-9268HIGHCVSS 7.2EG 7.22016-11-10
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with …
- CVE-2016-9492CRITICALCVSS 9.8EG 9.82018-07-13
The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous e…
- CVE-2017-1000081CRITICALCVSS 9.8EG 9.82017-07-17
Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.
- CVE-2017-1000119HIGHCVSS 7.2EG 8.22017-10-05
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.
- CVE-2017-1000194CRITICALCVSS 9.8EG 9.82017-11-17
October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly other applications on the server.
- CVE-2017-1000238HIGHCVSS 8.8EG 8.82017-11-17
InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserv…
- CVE-2017-1002000CRITICALCVSS 9.8EG 9.82017-09-14
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload conte…
- CVE-2017-1002001CRITICALCVSS 9.8EG 9.82017-09-14
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
- CVE-2017-1002002CRITICALCVSS 9.8EG 9.82017-09-14
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/
- CVE-2017-1002003CRITICALCVSS 9.8EG 9.82017-09-14
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
- CVE-2017-1002008CRITICALCVSS 9.8EG 9.82017-09-14
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileg…
- CVE-2017-1002016CRITICALCVSS 9.8EG 9.82017-09-14
Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to see if the user is authenticated or that they have permission to upload files.
- CVE-2017-10940HIGHCVSS 8.8EG 8.82017-10-31
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Joyent Smart Data Center prior to [email protected] (e469cf49-4de3-4658-8419-ab42837916ad). An at…
- CVE-2017-11154HIGHCVSS 7.2EG 7.22017-08-08
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to create arbitrary PHP scripts via the type parameter.
- CVE-2017-11326HIGHCVSS 7.5EG 7.52017-07-24
An issue was discovered in Tilde CMS 1.0.1. It is possible to bypass the implemented restrictions on arbitrary file upload via a filename.+php manipulation.
- CVE-2017-11357CRITICALCVSS 9.8EG 9.8⚠ KEV2017-08-23
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
- CVE-2017-11404MEDIUMCVSS 4.9EG 4.92017-07-18
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a FileManager action to admin/moduleinterface.php.
- CVE-2017-11405MEDIUMCVSS 4.9EG 4.92017-07-18
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a CMSContentManager action to admin/moduleinterface.php, followed by a FilePicker action to admin/moduleinterface.php in which type=image is c…
- CVE-2017-11466HIGHCVSS 7.2EG 7.22017-07-20
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrators to upload .jsp files to arbitrary locations via directory traversal sequences in the fi…
- CVE-2017-11561MEDIUMCVSS 6.5EG 6.52019-05-23
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
- CVE-2017-11756HIGHCVSS 7.0EG 7.02017-07-30
In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload extensions to include .php in addition to .mp3 and .m4a in admin.php?iframe=config_upload, and…
- CVE-2017-12332MEDIUMCVSS 4.4EG 4.42017-11-30
A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, local attacker to write a file to arbitrary locations. The vulnerability is due to insufficient restrictions in the patch installation process.…
- CVE-2017-12615CRITICALCVSS 8.1EG 9.0⚠ KEV2017-09-19
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted reques…
- CVE-2017-12617CRITICALCVSS 8.1EG 9.0⚠ KEV2017-10-04
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible…
- CVE-2017-12678HIGHCVSS 8.8EG 8.82017-08-08
In TagLib 1.11.1, the rebuildAggregateFrames function in id3v2framefactory.cpp has a pointer to cast vulnerability, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted audio fi…
- CVE-2017-12929HIGHCVSS 8.8EG 8.82017-09-21
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Execution.
- CVE-2017-13156HIGHCVSS 7.8EG 7.82017-12-06
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847.
- CVE-2017-13982HIGHCVSS 8.8EG 8.82017-09-30
A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows users to upload unrestricted files.
- CVE-2017-14050HIGHCVSS 8.8EG 8.82017-08-31
In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .php file.
- CVE-2017-14079HIGHCVSS 8.8EG 8.82017-09-22
Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
- CVE-2017-14123HIGHCVSS 8.8EG 8.82017-09-04
Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute …
- CVE-2017-14251HIGHCVSS 8.8EG 8.82017-09-11
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and …
- CVE-2017-14346CRITICALCVSS 9.8EG 9.82017-09-12
upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file.
- CVE-2017-14399HIGHCVSS 8.8EG 8.82017-09-12
In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing the extension from .jpg to .php.
- CVE-2017-14521HIGHCVSS 8.8EG 8.82018-01-26
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
- CVE-2017-14704HIGHCVSS 8.8EG 8.82017-09-26
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable e…
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →