CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,022 vulnerabilities with CWE-434
CVE-2016-1713 HIGH
Vtiger CRM 6.4.0 - RCE
CVSS 7.3
CVE-2016-8973 MEDIUM
IBM Rhapsody DM <6.0 - Privilege Escalation
CVSS 4.3
CVE-2016-6104 HIGH
IBM Tivoli Key Lifecycle Manager <2.7 - RCE
CVSS 7.2
CVE-2016-8921 HIGH
IBM FileNet WorkPlace XT - RCE
CVSS 8.8
CVE-2016-6124 HIGH
IBM Kenexa LMS on Cloud 13.1-13.2.4 - RCE
CVSS 8.8
CVE-2016-7902 HIGH
Dotclear < 2.10.2 - Unrestricted File Upload
CVSS 8.8
CVE-2016-9268 HIGH
Dotclear <2.10.4 - RCE
CVSS 7.2
CVE-2016-9187 HIGH
Moodle 3.1.2 - RCE
CVSS 8.8
CVE-2016-9186 HIGH
Moodle 3.1.2 - RCE
CVSS 8.8
CVE-2016-7452 HIGH
Exponentcms Exponent Cms < 2.3.9 - Unrestricted File Upload
CVSS 7.5
CVE-2016-7095 CRITICAL
Exponentcms Exponent Cms < 2.3.8 - Unrestricted File Upload
CVSS 9.8
CVE-2016-5050 CRITICAL
Readydesk - Unrestricted File Upload
CVSS 9.8
CVE-2016-2914 MEDIUM
IBM Engineering Lifecycle Optimizatio... - Unrestricted File Upload
CVSS 5.4
CVE-2016-3088 CRITICAL KEV
ActiveMQ web shell upload
CVSS 9.8
CVE-2015-10144 HIGH
Responsive Thumbnail Slider <1.0.1 - Code Injection
CVSS 8.8
CVE-2015-10137 CRITICAL
Website Contact Form With File Upload <1.3.4 - RCE
CVSS 9.8
CVE-2015-10138 CRITICAL
The Work The Flow File Upload plugin - Path Traversal
CVSS 9.8
CVE-2015-10135 CRITICAL
WPshop <1.3.9.6 - RCE
CVSS 9.8
CVE-2015-10087 MEDIUM
UpThemes Theme DesignFolio Plus 1.2 - Unrestricted Upload
CVSS 6.3
CVE-2015-1785 MEDIUM
Imagely Nextgen Gallery < 2.0.77.3 - CSRF
CVSS 6.5
CVE-2015-1784 HIGH
Imagely Nextgen Gallery < 2.0.77.3 - Unrestricted File Upload
CVSS 8.8
CVE-2015-7341 HIGH
Joobi Jnews < 8.5.0 - Unrestricted File Upload
CVSS 8.8
CVE-2015-7339 HIGH
Widgetfactorylimited Jce < 2.5.2 - Unrestricted File Upload
CVSS 8.8
CVE-2015-0258 HIGH
O-dyn Collabtive < 2.1 - Unrestricted File Upload
CVSS 8.8
CVE-2015-6000 HIGH
Vtiger CRM <6.3.0 - RCE
CVSS 8.8
Details
Vulnerabilities 4,022
Exploit Likelihood Medium