Fallos del tipo CWE-434

3083 resultados

Upload irrestrito de arquivo com tipo perigoso

Ocorre quando a aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos. O risco é grave: o arquivo pode ser armazenado em local acessível pela web, executado pelo servidor, ou baixado e executado pela vítima.

Ejemplo

Um formulário de perfil aceita qualquer arquivo como 'foto', sem verificação. Alguém faz upload de um .exe ou .php; se salvo em pasta pública e com permissões erradas, o arquivo pode ser executado pelo servidor ou baixado por outros usuários.

Cómo mitigar

Valide a extensão e o tipo MIME no servidor (nunca apenas no cliente), rejeite extensões perigosas explicitamente, armazene uploads fora da raiz web ou sem permissão de execução, e considere renomear arquivos removendo extensão original. Idealmente, converta imagens para formatos seguros (PNG/JPG) após upload.

CVE-2022-40407HIGHA zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.EPSS 1.3%CVE-2023-3295HIGHUnlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.66 - Authenticated (Contributor+) Arbitrary File UploadEPSS 1.3%CVE-2022-45802CRITICALApache StreamPark (incubating): Upload any file to any directoryEPSS 1.3%CVE-2012-10044CRITICALMobileCartly 1.0 savepage.php Arbitrary File CreationEPSS 1.3%CVE-2012-10050CRITICALCuteFlow <= 2.11.2 Arbitrary File Upload RCEEPSS 1.3%CVE-2012-10027CRITICALWordPress Plugin WP-Property <= 1.35.0 PHP File UploadEPSS 1.3%CVE-2020-36897CRITICALQiHang Media Web Digital Signage 3.0.9 Unauthenticated Remote Code ExecutionEPSS 1.3%CVE-2019-10935—A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.EPSS 1.3%CVE-2021-28998HIGHFile upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar fileEPSS 1.3%CVE-2023-2712CRITICALMalicious File Upload vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform.EPSS 1.3%CVE-2024-53345HIGHAn authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to execute arbitrary codeEPSS 1.3%CVE-2022-50898HIGHNanoCMS 0.4 - Remote Code Execution (RCE) (Authenticated)EPSS 1.3%CVE-2021-27489—ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file couEPSS 1.3%CVE-2022-41385CRITICALThe d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdooEPSS 1.3%CVE-2021-26634CRITICALMaxboard multiple vulnerabilitiesEPSS 1.3%CVE-2022-42037CRITICALThe d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdooEPSS 1.3%CVE-2022-41384CRITICALThe d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backEPSS 1.3%CVE-2022-41386CRITICALThe d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backEPSS 1.3%CVE-2022-41387CRITICALThe d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdooEPSS 1.3%CVE-2022-41383CRITICALThe d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The bacEPSS 1.3%