Weaknesses of type CWE-434

3,092 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2026-81402CRITICALDS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File UploadEPSS 0.8%CVE-2025-6679CRITICALContact Form by Bit Form - Bit Form <= 2.20.3 - Unauthenticated Arbitrary File UploadEPSS 0.8%CVE-2024-42991HIGHMCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.EPSS 0.8%CVE-2023-29102CRITICALWordPress Olive One Click Demo Import Plugin <= 1.1.1 is vulnerable to Arbitrary File UploadEPSS 0.8%CVE-2020-19786HIGHFile upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP fiEPSS 0.8%CVE-2024-0185MEDIUMRRJ Nueva Ecija Engineer Online Portal Avatar dasboard_teacher.php unrestricted uploadEPSS 0.8%CVE-2022-47766HIGHPopojiCMS v2.0.1 backend plugin function has a file upload vulnerability.EPSS 0.8%CVE-2026-72592CRITICALdulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File UploadEPSS 0.8%CVE-2024-6115MEDIUMitsourcecode Simple Online Hotel Reservation System add_room.php unrestricted uploadEPSS 0.8%CVE-2024-6110MEDIUMitsourcecode Magbanua Beach Resort Online Reservation System controller.php unrestricted uploadEPSS 0.8%CVE-2024-6116MEDIUMitsourcecode Simple Online Hotel Reservation System edit_room.php unrestricted uploadEPSS 0.8%CVE-2024-3369MEDIUMcode-projects Car Rental add-vehicle.php unrestricted uploadEPSS 0.8%CVE-2023-27246HIGHAn arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a cEPSS 0.8%CVE-2026-63223CRITICALCodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rulesEPSS 0.8%CVE-2024-33786CRITICALAn arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code viEPSS 0.8%CVE-2026-9102CRITICALPath Traversal in Altium Enterprise Server ComparisonService Allows Arbitrary File WriteEPSS 0.8%CVE-2019-25647HIGHPhreeBooks ERP 5.2.3 Remote Code Execution via Image ManagerEPSS 0.8%CVE-2023-34136—Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the EPSS 0.8%CVE-2026-55633HIGHDataEase H2 RCE via Zip Protocol & File Dropper Fix bypassEPSS 0.8%CVE-2024-1035HIGHopenBI Icon.php uploadIcon unrestricted uploadEPSS 0.8%