Weaknesses of type CWE-434

3,090 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2019-12803HIGHHunesion i-oneNet unrestricted file upload vulnerabilityEPSS 1.9%CVE-2022-40087CRITICALSimple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulneEPSS 1.8%CVE-2017-6041—An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A32EPSS 1.8%CVE-2023-5492MEDIUMByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform licence.php unrestricted uploadEPSS 1.8%CVE-2023-5488MEDIUMByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform updatelib.php unrestricted uploadEPSS 1.8%CVE-2024-2221CRITICALPath Traversal and Arbitrary File Upload Vulnerability in qdrant/qdrantEPSS 1.8%CVE-2021-24254—College Publisher Import <= 0.1 - Arbitrary File Upload to RCEEPSS 1.8%CVE-2020-12005—FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ContEPSS 1.8%CVE-2013-10054CRITICALLibrettoCMS File Manager Arbitrary File UploadEPSS 1.8%CVE-2013-10038CRITICALFlashChat Arbitrary File Upload RCEEPSS 1.8%CVE-2023-4225HIGHChamilo LMS File Upload Functionality Remote Code ExecutionEPSS 1.8%CVE-2024-51793CRITICALWordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerabilityEPSS 1.8%CVE-2023-4223HIGHChamilo LMS File Upload Functionality Remote Code ExecutionEPSS 1.8%CVE-2023-4224HIGHChamilo LMS File Upload Functionality Remote Code ExecutionEPSS 1.8%CVE-2022-45771HIGHAn issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crEPSS 1.8%CVE-2020-36706CRITICALSimple:Press – WordPress Forum Plugin <= 6.6.0 - Arbitrary File UploadEPSS 1.8%CVE-2017-16736—An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remEPSS 1.8%CVE-2019-1010062—PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type. The impact is: get webshell. The componeEPSS 1.8%CVE-2025-67506CRITICALPipesHub Vulnerable to Path Traversal through Unauthenticated Arbitrary File UploadEPSS 1.8%CVE-2024-7694HIGHTeamT5 ThreatSonar Anti-Ransomware - Arbitrary File UploadEPSS 1.8%KEV