VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 102 of 216
  • CVE-2020-26804HigNov 12, 2020
    risk 0.57cvss 8.8epss 0.01

    In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with the shared announcements. This "Upload Attachment" functionality is suffered from "Unrestricted File Upload" vulnerability so…

  • CVE-2020-26803HigNov 12, 2020
    risk 0.57cvss 8.8epss 0.01

    In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this functionality and control the server.

  • CVE-2020-26048HigOct 5, 2020
    risk 0.57cvss 8.8epss 0.02

    The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file manager is able to modify the image extension into PHP…

  • CVE-2020-12715HigSep 30, 2020
    risk 0.57cvss 8.8epss 0.01

    RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control.

  • CVE-2020-21564HigSep 30, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.

  • CVE-2020-25149HigSep 25, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other…

  • CVE-2020-25145HigSep 25, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other…

  • CVE-2020-25144HigSep 25, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other…

  • CVE-2020-25136HigSep 25, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other…

  • CVE-2020-25134HigSep 25, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other…

  • CVE-2020-25133HigSep 25, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other…

  • CVE-2020-14022HigSep 22, 2020
    risk 0.57cvss 8.8epss 0.02

    Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contacts" functionality) from a file. It is possible to upload an executable or .bat file that can be executed with the help of a functionality (E.g. the…

  • CVE-2020-10228HigSep 14, 2020
    risk 0.57cvss 8.8epss 0.03

    A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote code execution.

  • CVE-2020-23829HigSep 1, 2020
    risk 0.57cvss 8.8epss 0.03

    interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

  • CVE-2020-14488HigJul 29, 2020
    risk 0.57cvss 8.8epss 0.02

    OpenClinic GA 5.09.02 and 5.89.05b does not properly verify uploaded files, which may allow a low-privilege user to upload and execute arbitrary files on the system.

  • CVE-2020-9309HigJul 15, 2020
    risk 0.57cvss 8.8epss 0.02

    Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file extensions (for example HTML code in a TXT file). When these files are stored as protected or draft files, the MIME detection can cause browsers to execute the…

  • CVE-2020-14066HigJul 15, 2020
    risk 0.57cvss 8.8epss 0.02

    IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access.

  • CVE-2020-12854HigJul 15, 2020
    risk 0.57cvss 8.8epss 0.03

    A remote code execution vulnerability was identified in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can invoke code execution upon uploading a carefully crafted JPEG file as part of the profile avatar.

  • CVE-2020-13887HigJun 22, 2020
    risk 0.57cvss 8.8epss 0.02

    documents_add.php in Kordil EDMS through 2.2.60rc3 allows Remote Command Execution because .php files can be uploaded to the documents folder.

  • CVE-2020-12675HigMay 29, 2020
    risk 0.57cvss 8.8epss 0.03

    The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution. NOTE: this issue exists because of an…