CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,021 vulnerabilities with CWE-434
CVE-2018-11091 CRITICAL
Mybiz Myprocurenet - Unrestricted File Upload
CVSS 9.9
CVE-2018-0587 MEDIUM
Ultimatemember User Profile & Membership - Unrestricted File Upload
CVSS 4.3
CVE-2018-0568 HIGH
Sitebridge Joruri GW < 3.2.0 - Unrestricted File Upload
CVSS 8.8
CVE-2018-10942 CRITICAL
Attribute Wizard - Unrestricted File Upload
CVSS 9.8
CVE-2018-2420 MEDIUM
SAP Internet Graphics Server - Unrestricted File Upload
CVSS 6.5
CVE-2018-10795 HIGH
Liferay Portal < 6.2.5 - Unrestricted File Upload
CVSS 8.8
CVE-2018-0258 CRITICAL
Cisco Prime Data Center Network Manager - Path Traversal
CVSS 9.8
CVE-2018-10577 HIGH
WatchGuard AP100-AP200/AP300 <1.2.9.15/<2.0.0.10 - RCE
CVSS 8.8
CVE-2018-10521 LOW
CMSMS <2.2.7 - DoS
CVSS 2.7
CVE-2018-10469 CRITICAL
b3log Symphony <2.6.0 - RCE
CVSS 9.8
CVE-2018-10375 CRITICAL
DedeCMS V5.7 SP2 - RCE
CVSS 9.8
CVE-2018-10173 HIGH
Digital Guardian Management Console 7.1.2.0015 - Authenticated RCE
CVSS 8.8
CVE-2018-9153 HIGH
Zblogcn Z-blogphp - Unrestricted File Upload
CVSS 7.2
CVE-2018-9037 HIGH
Monstra - Unrestricted File Upload
CVSS 8.8
CVE-2018-2404 MEDIUM
SAP Disclosure Management - Unrestricted File Upload
CVSS 4.3
CVE-2018-9157 HIGH
Axis M1033-w Firmware - Unrestricted File Upload
CVSS 7.5
CVE-2018-9156 HIGH
Axis P1354 Firmware - Unrestricted File Upload
CVSS 7.5
CVE-2018-8944 CRITICAL
Phpok - Unrestricted File Upload
CVSS 9.8
CVE-2018-8766 CRITICAL
joyplus-cms 1.6.0 - RCE
CVSS 9.8
CVE-2018-1000094 HIGH
CMS Made Simple <2.2.5 - Authenticated RCE
CVSS 7.2
CVE-2018-7562 HIGH
Glpi < 9.2.1 - Race Condition
CVSS 7.5
CVE-2018-1215 HIGH
Dell Emc Solutions Enabler Virtual Ap... - Unrestricted File Upload
CVSS 8.8
CVE-2018-7665 CRITICAL
Clip-bucket Clipbucket < 4.0.0 - Unrestricted File Upload
CVSS 9.8
CVE-2018-7567 HIGH
Otrs < 5.0.23 - Unrestricted File Upload
CVSS 7.2
CVE-2018-7316 CRITICAL
Christianwebministries Proclaim - Unrestricted File Upload
CVSS 9.8
Details
Vulnerabilities 4,021
Exploit Likelihood Medium