CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,276 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 5 of 86
- CVE-2017-14838HIGHCVSS 8.8EG 8.82017-09-28
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
- CVE-2017-14839HIGHCVSS 8.8EG 8.82017-09-28
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
- CVE-2017-14840HIGHCVSS 8.8EG 8.82017-09-28
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
- CVE-2017-14841MEDIUMCVSS 6.5EG 6.52017-09-28
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.
- CVE-2017-14958HIGHCVSS 7.2EG 7.22017-10-02
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file.
- CVE-2017-1499HIGHCVSS 8.8EG 8.82018-02-14
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 129106.
- CVE-2017-15054HIGHCVSS 7.5EG 7.52017-11-27
An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. To exploit this vulnerability, an authenticated attacker has to t…
- CVE-2017-15549HIGHCVSS 8.8EG 8.82018-01-05
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privi…
- CVE-2017-15580CRITICALCVSS 9.8EG 9.82017-10-23
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modi…
- CVE-2017-15673HIGHCVSS 7.2EG 7.22017-11-28
The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP code via vectors involving a custom page.
- CVE-2017-15876HIGHCVSS 7.2EG 7.22017-12-19
Unrestricted File Upload vulnerability in GPWeb 8.4.61 allows remote authenticated users to upload any type of file, including a PHP shell.
- CVE-2017-15957HIGHCVSS 8.8EG 8.82017-10-29
my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.
- CVE-2017-15962CRITICALCVSS 9.8EG 9.82017-10-29
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
- CVE-2017-15990CRITICALCVSS 9.8EG 9.82017-10-31
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
- CVE-2017-16251HIGHCVSS 8.8EG 8.82018-03-13
A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious script to the Personal Library by a crafted POST request. Successful exploit could allow an a…
- CVE-2017-16524HIGHCVSS 8.8EG 8.82017-11-06
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrary PHP code via a filename with a .php ex…
- CVE-2017-16594MEDIUMCVSS 6.5EG 6.52018-01-23
This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing auth…
- CVE-2017-16736HIGHCVSS 7.5EG 7.52018-01-12
An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remote attacker to upload arbitrary files.
- CVE-2017-16772HIGHCVSS 8.8EG 8.82018-03-22
Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes via the prog_id parameter.
- CVE-2017-16941HIGHCVSS 8.8EG 8.82017-11-25
October CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote authenticated users to execute arbitrary PHP code by downloading a theme ZIP archive from /backend/cms/themes, and then uploading and importing a …
- CVE-2017-16949CRITICALCVSS 9.8EG 9.82017-12-19
An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the attacker to override the settings for allowed file extensions and upload file size, related…
- CVE-2017-17593HIGHCVSS 7.5EG 7.52017-12-13
Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/.
- CVE-2017-17727HIGHCVSS 8.8EG 8.82017-12-18
DedeCMS through 5.6 allows arbitrary file upload and PHP code execution by embedding the PHP code in a .jpg file, which is used in the templet parameter to member/article_edit.php.
- CVE-2017-17874HIGHCVSS 8.8EG 8.82017-12-27
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.
- CVE-2017-17976CRITICALCVSS 9.8EG 9.82018-01-26
In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.
- CVE-2017-17987HIGHCVSS 7.2EG 7.22017-12-30
PHP Scripts Mall Muslim Matrimonial Script allows arbitrary file upload via admin/mydetails_edit.php.
- CVE-2017-18048HIGHCVSS 8.8EG 8.92018-01-23
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.
- CVE-2017-18435HIGHCVSS 7.3EG 7.32019-08-02
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
- CVE-2017-18592HIGHCVSS 7.5EG 7.52019-08-27
The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
- CVE-2017-20021CRITICALCVSS 6.5EG 9.82022-06-09
A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the a…
- CVE-2017-20063MEDIUMCVSS 6.3EG 6.32022-06-20
A vulnerability was found in Elefant CMS 1.3.12-RC. It has been classified as critical. Affected is an unknown function of the file /filemanager/upload/drop of the component File Upload. The manipulation leads to improper privilege managem…
- CVE-2017-20224CRITICALCVSS 9.8EG 9.82026-03-16
Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious content by exploiting enabled WebDAV HTTP methods. Attackers can use PUT, DELETE, M…
- CVE-2017-2617HIGHCVSS 7.6EG 7.82018-05-22
hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.
- CVE-2017-2699HIGHCVSS 7.8EG 7.82017-11-22
The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could exploit this vulnerability to upload th…
- CVE-2017-2737HIGHCVSS 8.8EG 8.82017-11-22
VCM5010 with software versions earlier before V100R002C50SPC100 has an arbitrary file upload vulnerability. The software does not validate the files that uploaded. An authenticated attacker could upload arbitrary files to the system.
- CVE-2017-3108CRITICALCVSS 9.8EG 9.82017-08-11
Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.
- CVE-2017-3189HIGHCVSS 8.1EG 8.12018-07-24
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, there …
- CVE-2017-4990CRITICALCVSS 9.8EG 9.82017-06-21
In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which coul…
- CVE-2017-5520HIGHCVSS 8.8EG 8.82017-01-17
The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` exte…
- CVE-2017-6027CRITICALCVSS 9.8EG 9.82017-05-19
An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web S…
- CVE-2017-6041CRITICALCVSS 9.8EG 9.82017-06-30
An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Ca…
- CVE-2017-6090CRITICALCVSS 8.8EG 9.02017-10-03
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct re…
- CVE-2017-6104HIGHCVSS 7.5EG 7.52017-03-02
Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.
- CVE-2017-6931MEDIUMCVSS 6.5EG 6.52018-03-01
In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If you have implemented a Settings Tray form in contrib or a cu…
- CVE-2017-7281HIGHCVSS 8.8EG 8.82017-04-12
An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a rand…
- CVE-2017-7357CRITICALCVSS 9.1EG 9.12017-04-14
Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a file.
- CVE-2017-7429HIGHCVSS 8.8EG 8.82018-03-02
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
- CVE-2017-7695CRITICALCVSS 9.8EG 9.82017-04-11
Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety check and execute any code.
- CVE-2017-7989MEDIUMCVSS 6.5EG 6.52017-04-25
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
- CVE-2017-8080HIGHCVSS 8.8EG 8.82017-05-05
Atlassian Hipchat Server before 2.2.4 allows remote authenticated users with user level privileges to execute arbitrary code via vectors involving image uploads.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →