CWE-434
Medium likelihoodUnrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
4,022 vulnerabilities with CWE-434
CVE-2013-10055
CRITICAL
Havalite CMS 1.1.7 - Unauthenticated RCE
CVE-2013-10047
CRITICAL
MiniWeb HTTP Server <= Build 300 - File Upload
CVE-2013-10044
HIGH
OpenEMR < 4.1.1 Patch 14 - SQL Injection
CVSS 8.8
CVE-2013-10043
CRITICAL
OAstium VoIP PBX astium-confweb-2.1-25399 - Auth Bypass & RCE
CVE-2013-10040
CRITICAL
ClipBucket <2.6 - RCE
CVSS 9.8
CVE-2013-10038
CRITICAL
FlashChat <6.0.2-6.0.8 - RCE
CVE-2013-10034
CRITICAL
Kaseya KServer <6.3.0.2 - File Upload
CVE-2013-10032
HIGH
GetSimpleCMS <3.2.1 - Authenticated RCE
CVSS 8.8
CVE-2013-1916
HIGH
User Photo - Unrestricted File Upload
CVSS 8.8
CVE-2013-20002
CRITICAL
Themify Framework < 1.2.2 - Unrestricted File Upload
CVSS 9.8
CVE-2013-3684
CRITICAL
Imagely Nextgen Gallery < 1.9.13 - Unrestricted File Upload
CVSS 9.8
CVE-2013-2057
CRITICAL
Yabb < 2.5.2 - Unrestricted File Upload
CVSS 9.8
CVE-2013-0803
CRITICAL
PolarBear CMS 2.5 - RCE
CVSS 9.8
CVE-2013-3591
HIGH
Vtiger Crm - Unrestricted File Upload
CVSS 8.8
CVE-2013-2748
CRITICAL
Belkin Wemo Switch <WeMo_US_2.00.2176.PVT - Code Injection
CVSS 9.8
CVE-2013-7390
CRITICAL
ManageEngine DesktopCentral <8.0.0 - RCE
CVSS 9.8
CVE-2013-6358
HIGH
Prestashop - Unrestricted File Upload
CVSS 8.8
CVE-2013-4796
HIGH
ReviewBoard <1.6.17 - Code Injection
CVSS 8.8
CVE-2013-6234
HIGH
ENG Spagobi < 4.1 - Unrestricted File Upload
CVSS 8.0
CVE-2013-7426
CRITICAL
kamailio 4.0.1 - Info Disclosure
CVSS 9.8
CVE-2012-10064
CRITICAL
Omni Secure Files <0.1.14 - RCE
CVE-2012-10062
HIGH
XAMPP 1.7.3 - RCE
CVE-2012-10056
HIGH
PHP Volunteer Management System v1.0.2 - Code Injection
CVE-2012-10054
CRITICAL
Umbraco CMS <4.7.1 - RCE
CVSS 9.8
CVE-2012-10038
CRITICAL
Auxilium RateMyPet - RCE
Details
Vulnerabilities
4,022
Exploit Likelihood
Medium