Falhas do tipo CWE-434

3.082 resultados

Upload irrestrito de arquivo com tipo perigoso

A aplicação aceita upload de arquivos sem validar adequadamente o tipo ou extensão, permitindo que um atacante envie executáveis, scripts ou outros arquivos maliciosos que serão armazenados ou executados no servidor. O risco aumenta se o arquivo for salvo em diretório acessível pela web ou em local onde será processado automaticamente.

Exemplo

Um sistema de upload de 'fotos de perfil' verifica apenas o tamanho do arquivo, mas não valida a extensão. Um atacante envia um arquivo .php disfarçado de imagem; se salvo em /uploads/ acessível via web, ele consegue executar código PHP no servidor ao acessar a URL direta.

Como mitigar

Valide extensões contra uma lista branca (whitelist) de tipos permitidos, verifique a assinatura do arquivo (magic bytes) e não confie apenas no Content-Type do cliente. Armazene uploads fora do diretório web ou configure o servidor para não executar scripts no diretório de uploads.

CVE-2022-40087CRITICALSimple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulneEPSS 1.8%CVE-2017-6041An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A32EPSS 1.8%CVE-2023-5488MEDIUMByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform updatelib.php unrestricted uploadEPSS 1.8%CVE-2023-5492MEDIUMByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform licence.php unrestricted uploadEPSS 1.8%CVE-2024-2221CRITICALPath Traversal and Arbitrary File Upload Vulnerability in qdrant/qdrantEPSS 1.8%CVE-2021-24254College Publisher Import <= 0.1 - Arbitrary File Upload to RCEEPSS 1.8%CVE-2020-12005FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ContEPSS 1.8%CVE-2013-10038CRITICALFlashChat Arbitrary File Upload RCEEPSS 1.8%CVE-2023-4223HIGHChamilo LMS File Upload Functionality Remote Code ExecutionEPSS 1.8%CVE-2023-4225HIGHChamilo LMS File Upload Functionality Remote Code ExecutionEPSS 1.8%CVE-2024-51793CRITICALWordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerabilityEPSS 1.8%CVE-2023-4224HIGHChamilo LMS File Upload Functionality Remote Code ExecutionEPSS 1.8%CVE-2022-45771HIGHAn issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crEPSS 1.8%CVE-2020-36706CRITICALSimple:Press – WordPress Forum Plugin <= 6.6.0 - Arbitrary File UploadEPSS 1.8%CVE-2017-16736An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remEPSS 1.8%CVE-2019-1010062PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type. The impact is: get webshell. The componeEPSS 1.8%CVE-2025-67506CRITICALPipesHub Vulnerable to Path Traversal through Unauthenticated Arbitrary File UploadEPSS 1.8%CVE-2024-7694HIGHTeamT5 ThreatSonar Anti-Ransomware - Arbitrary File UploadEPSS 1.8%KEVCVE-2021-4354HIGHPWA for WP & AMP <= 1.7.32 - Arbitrary File UploadEPSS 1.8%CVE-2023-5822HIGHDrag and Drop Multiple File Upload - Contact Form 7 <= 1.3.7.3 - Unauthenticated Arbitrary File UploadEPSS 1.8%