CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,022 vulnerabilities with CWE-434
CVE-2017-14123 HIGH
Zoho ManageEngine Firewall Analyzer 12200 - RCE
CVSS 8.8
CVE-2017-14050 HIGH
BlackCat CMS 1.2 - Authenticated RCE
CVSS 8.8
CVE-2017-9650 HIGH
ALC WebCTRL <6.5 - RCE
CVSS 7.8
CVE-2017-11357 CRITICAL KEV
Telerik UI For Asp.net Ajax < 2020.1.114 - Unrestricted File Upload
CVSS 9.8
CVE-2017-3108 CRITICAL
Adobe Experience Manager < 6.2 - Unrestricted File Upload
CVSS 9.8
CVE-2017-11154 HIGH
Synology Photo Station < 6.7.2-3429 - Unrestricted File Upload
CVSS 7.2
CVE-2017-12678 HIGH
Taglib - Unrestricted File Upload
CVSS 8.8
CVE-2017-11756 HIGH
Ear Music <4.1 build 20170710 - RCE
CVSS 7.0
CVE-2017-11326 HIGH
Tilde Cms - Unrestricted File Upload
CVSS 7.5
CVE-2017-11466 HIGH
dotCMS 4.1.1 - RCE
CVSS 7.2
CVE-2017-11405 MEDIUM
Cmsmadesimple Cms Made Simple - Unrestricted File Upload
CVSS 4.9
CVE-2017-11404 MEDIUM
Cmsmadesimple Cms Made Simple - Unrestricted File Upload
CVSS 4.9
CVE-2017-1000081 CRITICAL
Linux Foundation ONOS 1.9.0 - RCE
CVSS 9.8
CVE-2017-6041 CRITICAL
Marel A320 Firmware - Unrestricted File Upload
CVSS 9.8
CVE-2017-9840 HIGH
Dolibarr ERP/CRM <5.0.3 - Code Injection
CVSS 8.8
CVE-2017-4990 CRITICAL
EMC Avamar Server Software <7.4.1-58 - RCE
CVSS 9.8
CVE-2017-9380 HIGH
OpenEMR <5.0.0 - Code Injection
CVSS 8.8
CVE-2017-9364 CRITICAL
BigTree CMS <4.2.18 - Code Injection
CVSS 9.8
CVE-2017-9101 CRITICAL
PlaySMS 1.4 - RCE
CVSS 9.8
CVE-2017-9080 HIGH
PlaySMS 1.4 - RCE
CVSS 8.8
CVE-2017-6027 CRITICAL
Codesys Web Server < 2.3 - Unrestricted File Upload
CVSS 9.8
CVE-2017-9069 HIGH
MODX Revolution <2.5.7 - Code Injection
CVSS 8.8
CVE-2017-8080 HIGH
Atlassian Hipchat Server < 2.2.3 - Unrestricted File Upload
CVSS 8.8
CVE-2017-7989 MEDIUM
Joomla! - Unrestricted File Upload
CVSS 6.5
CVE-2017-7357 CRITICAL
Hipchat Server <2.2.3 - RCE
CVSS 9.1
Details
Vulnerabilities 4,022
Exploit Likelihood Medium