VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 127 of 216
  • CVE-2022-26619HigApr 5, 2022
    risk 0.49cvss 7.5epss 0.01

    Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.

  • CVE-2021-32961HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip command and place a malicious .exe file in one of the…

  • CVE-2021-37194HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS…

  • CVE-2021-24981HigDec 21, 2021
    risk 0.49cvss 7.5epss 0.01

    The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.

  • CVE-2018-25019HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.02

    The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server

  • CVE-2021-37105HigSep 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an improper file upload control vulnerability in FusionCompute 6.5.0, 6.5.1 and 8.0.0. Due to the improper verification of file to be uploaded and does not strictly restrict the file access path, attackers may upload malicious files to the device, resulting in the…

  • CVE-2021-34639HigAug 5, 2021
    risk 0.49cvss 7.5epss 0.01

    Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and…

  • CVE-2021-3166HigJan 18, 2021
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when the filename Settings_DSL-N14U-B1.trx is used. Once this file is loaded, shutdown measures on a wide range of services are triggered as if it…

  • CVE-2020-35133HigDec 16, 2020
    risk 0.49cvss 7.5epss 0.04

    irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32+0xdb60.

  • CVE-2020-15488HigSep 30, 2020
    risk 0.49cvss 7.5epss 0.01

    Re:Desk 2.3 allows insecure file upload.

  • CVE-2020-12837HigSep 24, 2020
    risk 0.49cvss 7.5epss 0.01

    ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magic bytes of PNG must be used.

  • CVE-2020-25733HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.02

    webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.

  • CVE-2020-8162HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.03

    A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

  • CVE-2020-12005HigJun 15, 2020
    risk 0.49cvss 7.5epss 0.02

    FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx…

  • CVE-2020-13855HigJun 11, 2020
    risk 0.49cvss 7.2epss 0.28

    Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature.

  • CVE-2020-13852HigJun 11, 2020
    risk 0.49cvss 7.2epss 0.28

    Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.

  • CVE-2020-13128HigMay 18, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) accepts a delay parameter that causes a thread to sleep. It can be abused to cause all of a server's threads to sleep, leading to denial of service.

  • CVE-2019-18320HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could be able to upload arbitrary files without authentication. Please note that an attacker needs to have…

  • CVE-2019-17352HigOct 8, 2019
    risk 0.49cvss 7.5epss 0.02

    In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain…

  • CVE-2019-15862HigSep 26, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP,…