VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 128 of 216
  • CVE-2019-16720HigSep 23, 2019
    risk 0.49cvss 7.5epss 0.01

    ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.

  • CVE-2016-10958HigSep 16, 2019
    risk 0.49cvss 7.5epss 0.02

    The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php.

  • CVE-2017-18592HigAug 27, 2019
    risk 0.49cvss 7.5epss 0.01

    The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.

  • CVE-2015-9340HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.01

    The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.

  • CVE-2015-9339HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.01

    The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.

  • CVE-2015-9338HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.01

    The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.

  • CVE-2015-9341HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.01

    The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.

  • CVE-2019-1010209HigJul 23, 2019
    risk 0.49cvss 7.5epss 0.02

    GoUrl.io GoURL Wordpress Plugin 1.4.13 and earlier is affected by: CWE-434. The impact is: unauthenticated/unzuthorized Attacker can upload executable file in website. The component is: gourl.php#L5637. The fixed version is: 1.4.14.

  • CVE-2019-1010123HigJul 23, 2019
    risk 0.49cvss 7.5epss 0.01

    MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and content. The component is: Filtering user parameters before passing them into phpthumb class. The attack vector is: web…

  • CVE-2019-10930HigJul 11, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions ), DIGSI 5 engineering software (All versions < V7.90), SIPROTEC 5 device types 6MD85, 6MD86, 6MD89, 7UM85,…

  • CVE-2019-11807HigMay 6, 2019
    risk 0.49cvss 7.5epss 0.01

    The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.

  • CVE-2019-3489HigApr 1, 2019
    risk 0.49cvss 7.5epss 0.02

    An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. The vulnerability could be exploited by an unauthenticated remote attacker to…

  • CVE-2019-10012HigMar 25, 2019
    risk 0.49cvss 7.5epss 0.02

    Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archive and using the MoxieManager (for .NET) plugin before 2.1.4 in the moxiemanager directory within the installation folder…

  • CVE-2019-9692MedMar 11, 2019
    risk 0.49cvss 6.5epss 0.46

    class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).

  • CVE-2019-8433HigFeb 18, 2019
    risk 0.49cvss 7.5epss 0.01

    JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file.

  • CVE-2019-8362HigFeb 16, 2019
    risk 0.49cvss 7.5epss 0.01

    DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=save&formzip=1 request with a ZIP archive that contains a file such as "1.jpg.php" (because input validation only checks that .jpg,…

  • CVE-2019-7721HigFeb 11, 2019
    risk 0.49cvss 7.5epss 0.01

    lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata parameters.

  • CVE-2018-18771HigOct 29, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by entering a filename, directory name, and PHP code into the three text input fields.

  • CVE-2018-18315HigOct 15, 2018
    risk 0.49cvss 7.5epss 0.01

    com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFileToFile method in CdnUtils only checks for a ../ substring, and does not validate the file type and spaceName parameter.

  • CVE-2018-17055HigSep 28, 2018
    risk 0.49cvss 7.5epss 0.01

    An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.