VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 105 of 216
  • CVE-2019-13979HigJul 19, 2019
    risk 0.57cvss 8.8epss 0.03

    In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.

  • CVE-2019-4292HigJul 2, 2019
    risk 0.57cvss 8.8epss 0.04

    IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable web server. IBM X-Force ID: 160698.

  • CVE-2019-4069HigJun 7, 2019
    risk 0.57cvss 8.8epss 0.01

    IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. IBM X-Force ID: 157014.

  • CVE-2019-5357HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.03

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2016-10758HigMay 24, 2019
    risk 0.57cvss 8.8epss 0.02

    PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_name parameter.

  • CVE-2018-19612HigMay 24, 2019
    risk 0.57cvss 8.8epss 0.02

    The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload malicious file types and execute ASP code.

  • CVE-2019-11615HigApr 30, 2019
    risk 0.57cvss 8.8epss 0.01

    /fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can use this vulnerability to upload backdoor files to control the server.

  • CVE-2019-11568HigApr 27, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in AikCms v2.0. There is a File upload vulnerability, as demonstrated by an admin/page/system/nav.php request with PHP code in a .php file with the application/octet-stream content type.

  • CVE-2019-8992HigApr 24, 2019
    risk 0.57cvss 8.8epss 0.02

    The administrative server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO ActiveMatrix Service Grid…

  • CVE-2019-11377HigApr 20, 2019
    risk 0.57cvss 8.8epss 0.02

    wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension according to the fm_get_text_exts function.

  • CVE-2018-19453HigApr 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.

  • CVE-2019-11028HigApr 9, 2019
    risk 0.57cvss 8.8epss 0.03

    GAT-Ship Web Module before 1.40 suffers from a vulnerability allowing authenticated attackers to upload any file type to the server via the "Documents" area. This vulnerability is related to "uploadDocFile.aspx".

  • CVE-2019-9617HigMar 6, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadFile URI.

  • CVE-2019-9612HigMar 6, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/upload URI.

  • CVE-2019-9609HigMar 6, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/editUploadImage URI.

  • CVE-2019-9608HigMar 6, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadImage URI.

  • CVE-2018-20063HigFeb 25, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the image-upload form (available in the description editor), allowing remote authenticated users to execute arbitrary code by uploading an image file with an…

  • CVE-2019-8933HigFeb 19, 2019
    risk 0.57cvss 8.8epss 0.03

    In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execute this file, via this sequence of steps: visiting the management page, clicking on the template, clicking on Default Template…

  • CVE-2018-16169HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.

  • CVE-2018-1000839HigDec 20, 2018
    risk 0.57cvss 8.8epss 0.03

    LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.