VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,444)

page 124 of 223
  • CVE-2020-29176HigDec 2, 2021
    risk 0.51cvss 7.8epss 0.01

    An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute arbitrary code via a crafted JPG file.

  • CVE-2021-44094HigNov 28, 2021
    risk 0.51cvss 7.8epss 0.01

    ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file

  • CVE-2020-36485HigOct 22, 2021
    risk 0.51cvss 7.8epss 0.00

    Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted JPEG file.

  • CVE-2020-20672HigSep 13, 2021
    risk 0.51cvss 7.8epss 0.01

    An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted PHP file.

  • CVE-2021-38305HigAug 9, 2021
    risk 0.51cvss 7.8epss 0.02

    23andMe Yamale before 3.0.8 allows remote attackers to execute arbitrary code via a crafted schema file. The schema parser uses eval as part of its processing, and tries to protect from malicious expressions by limiting the builtins that are passed to the eval. When processing…

  • CVE-2020-19303HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.01

    An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2020-7864HigJun 15, 2021
    risk 0.51cvss 7.8epss 0.01

    Parameter manipulation can bypass authentication to cause file upload and execution. This will execute the remote code. This issue affects: Raonwiz DEXT5Editor versions prior to 3.5.1405747.1100.03.

  • CVE-2021-3277HigJun 7, 2021
    risk 0.51cvss 7.2epss 0.55

    Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.

  • CVE-2021-22698HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.04

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a stack-based buffer overflow to occur which could result in remote code execution when a malicious SSD file is…

  • CVE-2021-22697HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.03

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a use-after-free condition which could result in remote code execution when a malicious SSD file is uploaded and…

  • CVE-2020-4588HigOct 30, 2020
    risk 0.51cvss 7.8epss 0.01

    IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 184579.

  • CVE-2020-25515HigSep 22, 2020
    risk 0.51cvss 7.8epss 0.01

    Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http:///lms/index.php?page=books.

  • CVE-2020-25790HigSep 19, 2020
    risk 0.51cvss 7.2epss 0.16

    Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our security…

  • CVE-2020-25042HigSep 3, 2020
    risk 0.51cvss 7.2epss 0.18

    An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager) session and make a codebase/dir.php?type=filenew request to upload PHP code to codebase/handler.php.

  • CVE-2020-22722HigAug 14, 2020
    risk 0.51cvss 7.8epss 0.00

    Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker can obtain admin privileges by placing a malicious .exe file in the application and renaming it ScadaAgentSvc.exe, which would…

  • CVE-2020-22721HigAug 14, 2020
    risk 0.51cvss 7.8epss 0.00

    A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary code via the Miscellaneous " External Programs by uploading the malicious .exe file to the external program.

  • CVE-2020-17462HigAug 14, 2020
    risk 0.51cvss 7.8epss 0.01

    CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.

  • CVE-2020-13241HigMay 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file.

  • CVE-2020-11807HigMay 19, 2020
    risk 0.51cvss 7.8epss 0.01

    Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP code (and sometimes terminal commands) on a server by making an avatar update and then visiting the avatar file under the /images/…

  • CVE-2020-10963HigMar 25, 2020
    risk 0.51cvss 7.2epss 0.15

    FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued.