CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,316)
page 103 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-13384 | Hig | 0.57 | 8.8 | 0.03 | May 22, 2020 | Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example, .php filenames are blocked but .php7 filenames are not, a related issue to CVE-2017-18048. | ||
| CVE-2020-5577 | Hig | 0.57 | 8.8 | 0.02 | May 14, 2020 | Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type… | ||
| CVE-2019-16066 | Hig | 0.57 | 8.8 | 0.02 | Mar 19, 2020 | An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior. This allows an attacker to upload malicious files and perform arbitrary code execution on the system. | ||
| CVE-2020-9471 | Hig | 0.57 | 8.8 | 0.02 | Mar 16, 2020 | Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality. | ||
| CVE-2020-10557 | Hig | 0.57 | 8.8 | 0.01 | Mar 16, 2020 | An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section in the file manager page contains an arbitrary file upload vulnerability via upload.php. The extension .php7 bypasses file upload… | ||
| CVE-2015-7341 | Hig | 0.57 | 8.8 | 0.01 | Mar 9, 2020 | JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension. | ||
| CVE-2015-7339 | Hig | 0.57 | 8.8 | 0.01 | Mar 9, 2020 | JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script. | ||
| CVE-2018-19798 | Hig | 0.57 | 8.8 | 0.03 | Mar 2, 2020 | Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the application/x-php Content-Type to the accidents_add.php?submit=1 URI, as demonstrated by the value_Images_1 field, which leads to remote command execution on the remote… | ||
| CVE-2018-17058 | Hig | 0.57 | 8.8 | 0.01 | Mar 2, 2020 | An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload feature of ProductEdit.aspx. An authenticated attacker may bypass the frontend filename validation and upload an arbitrary file via… | ||
| CVE-2016-11020 | Cri | 0.57 | 9.8 | 0.03 | Feb 25, 2020 | Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution. | ||
| CVE-2011-1597 | Hig | 0.57 | 8.8 | 0.02 | Feb 6, 2020 | OpenVAS Manager v2.0.3 allows plugin remote code execution. | ||
| CVE-2020-7998 | Hig | 0.57 | 8.8 | 0.01 | Jan 28, 2020 | An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service. | ||
| CVE-2013-6358 | Hig | 0.57 | 8.8 | 0.04 | Jan 23, 2020 | PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory. | ||
| CVE-2019-20385 | Hig | 0.57 | 8.8 | 0.01 | Jan 21, 2020 | The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .php files with a text/* content type. The PHP code can then be executed by visiting a /supervisor/csv/ URI. | ||
| CVE-2020-5846 | Hig | 0.57 | 8.8 | 0.01 | Jan 6, 2020 | An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in the X-RSW-custom-encode-path HTTP header, and the content in the HTTP request body. It is possible… | ||
| CVE-2013-4796 | Hig | 0.57 | 8.8 | 0.02 | Dec 27, 2019 | ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request | ||
| CVE-2019-8293 | Cri | 0.57 | 9.8 | 0.03 | Dec 23, 2019 | Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution. | ||
| CVE-2019-19745 | Hig | 0.57 | 8.8 | 0.01 | Dec 17, 2019 | Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server. | ||
| CVE-2019-4612 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2019 | IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 168523. | ||
| CVE-2019-19684 | Hig | 0.57 | 8.8 | 0.02 | Dec 9, 2019 | nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure because it is possible to upload a crafted Facebook Auth plugin. |
- risk 0.57cvss 8.8epss 0.03
Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example, .php filenames are blocked but .php7 filenames are not, a related issue to CVE-2017-18048.
- risk 0.57cvss 8.8epss 0.02
Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type…
- risk 0.57cvss 8.8epss 0.02
An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior. This allows an attacker to upload malicious files and perform arbitrary code execution on the system.
- risk 0.57cvss 8.8epss 0.02
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section in the file manager page contains an arbitrary file upload vulnerability via upload.php. The extension .php7 bypasses file upload…
- risk 0.57cvss 8.8epss 0.01
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.
- risk 0.57cvss 8.8epss 0.01
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.
- risk 0.57cvss 8.8epss 0.03
Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the application/x-php Content-Type to the accidents_add.php?submit=1 URI, as demonstrated by the value_Images_1 field, which leads to remote command execution on the remote…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload feature of ProductEdit.aspx. An authenticated attacker may bypass the frontend filename validation and upload an arbitrary file via…
- risk 0.57cvss 9.8epss 0.03
Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.
- risk 0.57cvss 8.8epss 0.02
OpenVAS Manager v2.0.3 allows plugin remote code execution.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service.
- risk 0.57cvss 8.8epss 0.04
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.
- risk 0.57cvss 8.8epss 0.01
The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .php files with a text/* content type. The PHP code can then be executed by visiting a /supervisor/csv/ URI.
- risk 0.57cvss 8.8epss 0.01
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in the X-RSW-custom-encode-path HTTP header, and the content in the HTTP request body. It is possible…
- risk 0.57cvss 8.8epss 0.02
ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request
- risk 0.57cvss 9.8epss 0.03
Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution.
- risk 0.57cvss 8.8epss 0.01
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.
- risk 0.57cvss 8.8epss 0.01
IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 168523.
- risk 0.57cvss 8.8epss 0.02
nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure because it is possible to upload a crafted Facebook Auth plugin.