VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 104 of 216
  • CVE-2019-4130HigDec 3, 2019
    risk 0.57cvss 8.8epss 0.02

    IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 158280.

  • CVE-2019-17403HigNov 25, 2019
    risk 0.57cvss 8.8epss 0.03

    Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.

  • CVE-2010-3663HigNov 4, 2019
    risk 0.57cvss 8.8epss 0.02

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend.

  • CVE-2019-18204HigOct 30, 2019
    risk 0.57cvss 8.8epss 0.02

    Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution.

  • CVE-2018-18930HigOct 29, 2019
    risk 0.57cvss 8.8epss 0.03

    The Tightrope Media Carousel digital signage product 7.0.4.104 contains an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. An authenticated attacker can upload a crafted ZIP file (based on an…

  • CVE-2019-18417HigOct 24, 2019
    risk 0.57cvss 8.8epss 0.02

    Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution. The issue occurs because the application fails to adequately sanitize user-supplied input, e.g., "add a new food" allows .php files.

  • CVE-2019-17490HigOct 10, 2019
    risk 0.57cvss 8.8epss 0.01

    app\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload, as demonstrated by PHP code (with a .php filename but the image/png content type) to the web/polygon/problem/tests URI.

  • CVE-2019-14657HigOct 8, 2019
    risk 0.57cvss 8.8epss 0.04

    Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../../ allows replacement of almost any file on a phone. This leads to password…

  • CVE-2019-14656HigOct 8, 2019
    risk 0.57cvss 8.8epss 0.02

    Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.

  • CVE-2019-11655HigOct 4, 2019
    risk 0.57cvss 8.8epss 0.02

    Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type.

  • CVE-2019-15766HigOct 3, 2019
    risk 0.57cvss 8.8epss 0.03

    The KSLABS KSWEB (aka ru.kslabs.ksweb) application 3.93 for Android allows authenticated remote code execution via a POST request to the AJAX handler with the configFile parameter set to the arbitrary file to be written to (and the config_text parameter set to the content of the…

  • CVE-2015-9402HigSep 20, 2019
    risk 0.57cvss 8.8epss 0.02

    The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.

  • CVE-2019-6839HigSep 17, 2019
    risk 0.57cvss 8.8epss 0.01

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15),…

  • CVE-2019-15866HigSep 3, 2019
    risk 0.57cvss 8.8epss 0.02

    The crelly-slider plugin before 1.3.5 for WordPress has arbitrary file upload via a PHP file inside a ZIP archive to wp_ajax_crellyslider_importSlider.

  • CVE-2019-15649HigAug 27, 2019
    risk 0.57cvss 8.8epss 0.02

    The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.

  • CVE-2019-14755HigAug 15, 2019
    risk 0.57cvss 8.8epss 0.02

    The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type.

  • CVE-2019-5395HigAug 9, 2019
    risk 0.57cvss 8.8epss 0.02

    A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

  • CVE-2015-5601HigJul 29, 2019
    risk 0.57cvss 8.8epss 0.01

    edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.

  • CVE-2019-13984HigJul 19, 2019
    risk 0.57cvss 8.8epss 0.02

    Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direct link to each uploaded file, accessible by unauthenticated users, as demonstrated by the EICAR Anti-Virus Test File.

  • CVE-2019-13980HigJul 19, 2019
    risk 0.57cvss 8.8epss 0.02

    In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals remote code execution with nginx.