Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,278 CVEs tagged with CWE-4341,506 Critical, 1,644 High, 886 Medium, 241 Low, 1 Unrated.

CVE-2016-7902

Published Jan 4, 2017

Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9268

Published Nov 10, 2016

Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrato…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9187

Published Nov 4, 2016

Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploadi…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-9186

Published Nov 4, 2016

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7452

Published Nov 3, 2016

The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to upload a malicious file to any folder on the site via a cpi directory traversal.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7095

Published Nov 3, 2016

Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprotected folder, one allowing script execut…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-5050

Published Aug 26, 2016

Unrestricted file upload vulnerability in chat/sendfile.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary code by uploading and requesting a .aspx file.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-3088

Published Jun 1, 2016

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

CVSS 9.8 · Critical
evidence mentions
15
Buzz score
72.7
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2015-0702

Published Apr 21, 2015

Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated users to execute arbitrary co…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6994

Published Feb 12, 2007

Unrestricted file upload vulnerability in add.asp in OzzyWork Gallery, possibly 2.0 and earlier, allows remote attackers to upload and execute arbitrary ASP files by removing the…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5845

Published Nov 10, 2006

Unrestricted file upload vulnerability in index.php in Speedywiki 2.0 allows remote authenticated users to upload and execute arbitrary PHP code by setting the upload parameter to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4558

Published Sep 6, 2006

DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extens…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4471

Published Aug 31, 2006

The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2428

Published May 17, 2006

add.asp in DUware DUbanner 3.1 allows remote attackers to execute arbitrary code by uploading files with arbitrary extensions, such as ASP files, probably due to client-side enfor…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3288

Published Oct 23, 2005

Mailsite Express allows remote attackers to upload and execute files with executable extensions such as ASP by attaching the file using the "compose page" feature, then accessing…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1868

Published Jun 9, 2005

I-Man 0.9, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by uploading a file attachment with a .php extension.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1881

Published Jun 6, 2005

upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and exec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0254

Published May 2, 2005

BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files t…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-2262

Published Dec 31, 2004

ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the uplo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1841

Published Dec 31, 2002

The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP fi…

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 4,251-4,275 of 4,278 CVEsPage 171 of 172