CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code,
Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary cod
Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload t
Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbit
Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitra
Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbit
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin
Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE.
An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a websh
An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execut
The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader
An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix wh
The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload a
An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute ar
Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary cod
An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain
Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote comma
Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files
The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any co
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a we
Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.
Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to re
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePa
Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opene
Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary
Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' paramete
An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading
The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authe
Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The
In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to recei
An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a cr
Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php
Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote cod
ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, un
Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenti
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execut
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu
The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of f
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started