VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 103 of 216
  • CVE-2020-13384HigMay 22, 2020
    risk 0.57cvss 8.8epss 0.03

    Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example, .php filenames are blocked but .php7 filenames are not, a related issue to CVE-2017-18048.

  • CVE-2020-5577HigMay 14, 2020
    risk 0.57cvss 8.8epss 0.02

    Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type…

  • CVE-2019-16066HigMar 19, 2020
    risk 0.57cvss 8.8epss 0.02

    An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior. This allows an attacker to upload malicious files and perform arbitrary code execution on the system.

  • CVE-2020-9471HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.02

    Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.

  • CVE-2020-10557HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section in the file manager page contains an arbitrary file upload vulnerability via upload.php. The extension .php7 bypasses file upload…

  • CVE-2015-7341HigMar 9, 2020
    risk 0.57cvss 8.8epss 0.01

    JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.

  • CVE-2015-7339HigMar 9, 2020
    risk 0.57cvss 8.8epss 0.01

    JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.

  • CVE-2018-19798HigMar 2, 2020
    risk 0.57cvss 8.8epss 0.03

    Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the application/x-php Content-Type to the accidents_add.php?submit=1 URI, as demonstrated by the value_Images_1 field, which leads to remote command execution on the remote…

  • CVE-2018-17058HigMar 2, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload feature of ProductEdit.aspx. An authenticated attacker may bypass the frontend filename validation and upload an arbitrary file via…

  • CVE-2016-11020CriFeb 25, 2020
    risk 0.57cvss 9.8epss 0.03

    Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.

  • CVE-2011-1597HigFeb 6, 2020
    risk 0.57cvss 8.8epss 0.02

    OpenVAS Manager v2.0.3 allows plugin remote code execution.

  • CVE-2020-7998HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service.

  • CVE-2013-6358HigJan 23, 2020
    risk 0.57cvss 8.8epss 0.04

    PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.

  • CVE-2019-20385HigJan 21, 2020
    risk 0.57cvss 8.8epss 0.01

    The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .php files with a text/* content type. The PHP code can then be executed by visiting a /supervisor/csv/ URI.

  • CVE-2020-5846HigJan 6, 2020
    risk 0.57cvss 8.8epss 0.01

    An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in the X-RSW-custom-encode-path HTTP header, and the content in the HTTP request body. It is possible…

  • CVE-2013-4796HigDec 27, 2019
    risk 0.57cvss 8.8epss 0.02

    ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request

  • CVE-2019-8293CriDec 23, 2019
    risk 0.57cvss 9.8epss 0.03

    Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution.

  • CVE-2019-19745HigDec 17, 2019
    risk 0.57cvss 8.8epss 0.01

    Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.

  • CVE-2019-4612HigDec 9, 2019
    risk 0.57cvss 8.8epss 0.01

    IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 168523.

  • CVE-2019-19684HigDec 9, 2019
    risk 0.57cvss 8.8epss 0.02

    nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure because it is possible to upload a crafted Facebook Auth plugin.