VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 106 of 216
  • CVE-2018-19562HigNov 26, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip allows remote attackers to execute arbitrary code via a "Login Background > Program Upgrade > Compressed Packet Upgrade" action in which a .php file is inside a ZIP archive.

  • CVE-2018-0686HigNov 15, 2018
    risk 0.57cvss 8.8epss 0.01

    Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote authenticated attackers to upload and execute any executable files via unspecified vectors.

  • CVE-2018-18382HigOct 16, 2018
    risk 0.57cvss 8.8epss 0.03

    Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.

  • CVE-2018-18086HigOct 9, 2018
    risk 0.57cvss 8.8epss 0.01

    EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.

  • CVE-2018-17139HigSep 17, 2018
    risk 0.57cvss 8.8epss 0.03

    UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /products URI with PHP code in a .php file with the image/jpeg content type.

  • CVE-2018-16796HigSep 13, 2018
    risk 0.57cvss 8.8epss 0.03

    HiScout GRC Suite before 3.1.5 allows Unrestricted Upload of Files with Dangerous Types.

  • CVE-2018-16974CriSep 12, 2018
    risk 0.57cvss 9.8epss 0.04

    An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /filemanager/api/rm/.htaccess to remove the .htaccess file, and then using a filename that ends in .php followed by space characters (for…

  • CVE-2018-15882CriAug 29, 2018
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in Joomla! before 3.8.12. Inadequate checks in the InputFilter class could allow specifically prepared phar files to pass the upload filter.

  • CVE-2014-10074CriAug 27, 2018
    risk 0.57cvss 9.8epss 0.03

    Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the upload of .php files.

  • CVE-2018-1000646HigAug 20, 2018
    risk 0.57cvss 8.8epss 0.03

    LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.

  • CVE-2018-15573HigAug 20, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read and write data to any file on disk (as long as rlm.exe has access to it) via /goform/edit_lf_process with file content in the lfdata parameter and a pathname in…

  • CVE-2018-12940HigJul 31, 2018
    risk 0.57cvss 8.8epss 0.03

    Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension specified by the "qqfile" parameter. This allows an…

  • CVE-2018-14570HigJul 23, 2018
    risk 0.57cvss 8.8epss 0.02

    A file upload vulnerability in application/shop/controller/member.php in Niushop B2B2C Multi-business basic version V1.11 allows any remote member to upload a .php file to the web server via a profile avatar field, by using an image Content-Type (e.g., image/jpeg) with a…

  • CVE-2018-1000619HigJul 9, 2018
    risk 0.57cvss 8.8epss 0.02

    Ovidentia version 8.4.3 and earlier contains a Unsanitized User Input vulnerability in utilit.php, bab_getAddonFilePathfromTg that can result in Authenticated Remote Code Execution. This attack appear to be exploitable via The attacker must have permission to upload addons.

  • CVE-2018-12263HigJun 13, 2018
    risk 0.57cvss 8.8epss 0.01

    portfolioCMS 1.0.5 allows upload of arbitrary .php files via the admin/portfolio.php?newpage=true URI.

  • CVE-2018-1453HigJun 8, 2018
    risk 0.57cvss 8.8epss 0.02

    IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be automatically processed within the environment. IBM X-Force ID: 140055.

  • CVE-2018-11514HigMay 28, 2018
    risk 0.57cvss 8.8epss 0.01

    PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_resume_det.php, as demonstrated by changing .docx to .php.

  • CVE-2018-11345HigMay 22, 2018
    risk 0.57cvss 8.8epss 0.02

    An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the POST parameter filename. This can be used to place attacker controlled code on the file system that can then be executed. Further, the…

  • CVE-2018-10760HigMay 16, 2018
    risk 0.57cvss 8.8epss 0.01

    Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the tmp directory…

  • CVE-2018-0568HigMay 14, 2018
    risk 0.57cvss 8.8epss 0.02

    Unrestricted file upload vulnerability in SiteBridge Inc. Joruri Gw Ver 3.2.0 and earlier allows remote authenticated users to execute arbitrary PHP code via unspecified vectors.