Weaknesses of type CWE-434

3,091 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2023-30247CRITICALFile Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code EPSS 1.5%CVE-2023-51590CRITICALVoltronic Power ViewPower Pro UpLoadAction Unrestricted File Upload Remote Code Execution VulnerabilityEPSS 1.5%CVE-2025-3455HIGH1 Click WordPress Migration Plugin – 100% FREE for a limited time <= 2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File UploadEPSS 1.5%CVE-2024-43656CRITICALA backup can be manipulated and then restored to create arbitrary files inside the <redacted> directory. A CGI script can be added to the web directory this way, allowing for full remote code execution.EPSS 1.5%CVE-2014-125113CRITICALDell/Quest KACE K1000 Unauthenticated File Upload RCEEPSS 1.5%CVE-2022-1034CRITICALThere is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in star7th/showdocEPSS 1.5%CVE-2013-10047CRITICALMiniWeb <= Build 300 Arbitrary File UploadEPSS 1.5%CVE-2013-10067CRITICALGlossword 1.8.8 - 1.8.12 Arbitrary File Upload RCEEPSS 1.5%CVE-2024-28105HIGHphpMyFAQ's File Upload Bypass at Category Image Leads to RCEEPSS 1.5%CVE-2021-4080HIGHUnrestricted Upload of File with Dangerous Type in crater-invoice/craterEPSS 1.5%CVE-2022-1273—Import WP < 2.4.6 - Admin+ Arbitrary File Upload to RCEEPSS 1.5%CVE-2024-54262CRITICALWordPress Import Export For WooCommerce plugin <= 1.6.2 - Arbitrary File Upload vulnerabilityEPSS 1.5%CVE-2024-43657CRITICALWhen uploading new firmware, a shell script inside a firmware file is executed during its processing. This can be used to craft a custom firmware file with a custom script with arbitrary code, which will then be executed on the charging station.EPSS 1.5%CVE-2023-26578HIGHArbitrary File Upload to Web Root In IDAttend’s IDWeb ApplicationEPSS 1.5%CVE-2022-0687—Amelia < 1.0.46 - Manager+ RCEEPSS 1.5%CVE-2024-27311MEDIUMArbitrary file writingEPSS 1.5%CVE-2022-41437HIGHBilling System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProducEPSS 1.5%CVE-2024-37762CRITICALMachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.EPSS 1.5%CVE-2022-36386CRITICALWordPress Import any XML or CSV File to WordPress plugin <= 3.6.7 - Authenticated Arbitrary Code Execution vulnerabilityEPSS 1.5%CVE-2020-22151—Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests paramEPSS 1.5%