CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,022 vulnerabilities with CWE-434
CVE-2012-10052 CRITICAL
EGallery 1.2 - RCE
CVE-2012-10050 CRITICAL
CuteFlow <2.11.2 - RCE
CVE-2012-10049 CRITICAL
WebPageTest <2.6 - RCE
CVE-2012-10045 CRITICAL
XODA 0.4.5 - RCE
CVE-2012-10044 CRITICAL
MobileCartly 1.0 - File Creation
CVE-2012-10042 HIGH
Sflog! CMS 1.0 - Authenticated RCE
CVE-2012-10036 CRITICAL
Project Pier <0.8.8 - Unauthenticated RCE
CVE-2012-10030 CRITICAL
FreeFloat FTP Server - Unauthenticated RCE
CVSS 9.8
CVE-2012-10027 CRITICAL
WP-Property <1.35.0 - RCE
CVE-2012-10026 CRITICAL
Asset-Manager <2.0 - RCE
CVE-2012-10020 CRITICAL
FoxyPress <0.4.2.1 - File Upload
CVSS 9.8
CVE-2012-10019 CRITICAL
Front End Editor <2.3 - File Upload
CVSS 9.8
CVE-2012-6649 CRITICAL
Devfarm WP Gpx Maps - Unrestricted File Upload
CVSS 9.8
CVE-2012-5190 CRITICAL
Prizm Content Connect 5.1 - Code Injection
CVSS 9.8
CVE-2012-2950 HIGH
Gateway Geomatics MapServer <3.0.6 - Code Injection
CVSS 8.1
CVE-2012-2226 CRITICAL
Invisioncommunity Invision Power Board - Unrestricted File Upload
CVSS 9.8
CVE-2012-1592 HIGH
Apache Struts < 2.5.22 - Unrestricted File Upload
CVSS 8.8
CVE-2011-10041 CRITICAL
Uploadify WordPress plugin <1.0 - RCE
CVE-2011-10004 MEDIUM
Reciply < 1.1.8 - Unrestricted File Upload
CVSS 6.3
CVE-2011-4908 CRITICAL
Tinybrowser < 1.5.13 - Unrestricted File Upload
CVSS 9.8
CVE-2011-4906 CRITICAL
Tinybrowser < 1.5.13 - Unrestricted File Upload
CVSS 9.8
CVE-2011-1597 HIGH
OpenVAS Manager <2.0.3 - RCE
CVSS 8.8
CVE-2011-4907 MEDIUM
Joomla! < 1.5.12 - Unrestricted File Upload
CVSS 5.3
CVE-2011-2933 HIGH
Websitebaker < 2.8.1 - Unrestricted File Upload
CVSS 7.2
CVE-2011-1134 CRITICAL
S9Y Serendipity < 1.5.5 - Unrestricted File Upload
CVSS 9.8
Details
Vulnerabilities 4,022
Exploit Likelihood Medium