CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,316)
page 128 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16720 | Hig | 0.49 | 7.5 | 0.01 | Sep 23, 2019 | ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file. | ||
| CVE-2016-10958 | Hig | 0.49 | 7.5 | 0.02 | Sep 16, 2019 | The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php. | ||
| CVE-2017-18592 | Hig | 0.49 | 7.5 | 0.01 | Aug 27, 2019 | The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads. | ||
| CVE-2015-9340 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2019 | The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files. | ||
| CVE-2015-9339 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2019 | The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files. | ||
| CVE-2015-9338 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2019 | The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files. | ||
| CVE-2015-9341 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2019 | The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files. | ||
| CVE-2019-1010209 | Hig | 0.49 | 7.5 | 0.02 | Jul 23, 2019 | GoUrl.io GoURL Wordpress Plugin 1.4.13 and earlier is affected by: CWE-434. The impact is: unauthenticated/unzuthorized Attacker can upload executable file in website. The component is: gourl.php#L5637. The fixed version is: 1.4.14. | ||
| CVE-2019-1010123 | Hig | 0.49 | 7.5 | 0.01 | Jul 23, 2019 | MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and content. The component is: Filtering user parameters before passing them into phpthumb class. The attack vector is: web… | ||
| CVE-2019-10930 | Hig | 0.49 | 7.5 | 0.02 | Jul 11, 2019 | A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions ), DIGSI 5 engineering software (All versions < V7.90), SIPROTEC 5 device types 6MD85, 6MD86, 6MD89, 7UM85,… | ||
| CVE-2019-11807 | Hig | 0.49 | 7.5 | 0.01 | May 6, 2019 | The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks. | ||
| CVE-2019-3489 | Hig | 0.49 | 7.5 | 0.02 | Apr 1, 2019 | An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. The vulnerability could be exploited by an unauthenticated remote attacker to… | ||
| CVE-2019-10012 | Hig | 0.49 | 7.5 | 0.02 | Mar 25, 2019 | Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archive and using the MoxieManager (for .NET) plugin before 2.1.4 in the moxiemanager directory within the installation folder… | ||
| CVE-2019-9692 | Med | 0.49 | 6.5 | 0.46 | Mar 11, 2019 | class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG). | ||
| CVE-2019-8433 | Hig | 0.49 | 7.5 | 0.01 | Feb 18, 2019 | JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file. | ||
| CVE-2019-8362 | Hig | 0.49 | 7.5 | 0.01 | Feb 16, 2019 | DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=save&formzip=1 request with a ZIP archive that contains a file such as "1.jpg.php" (because input validation only checks that .jpg,… | ||
| CVE-2019-7721 | Hig | 0.49 | 7.5 | 0.01 | Feb 11, 2019 | lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata parameters. | ||
| CVE-2018-18771 | Hig | 0.49 | 7.5 | 0.01 | Oct 29, 2018 | An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by entering a filename, directory name, and PHP code into the three text input fields. | ||
| CVE-2018-18315 | Hig | 0.49 | 7.5 | 0.01 | Oct 15, 2018 | com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFileToFile method in CdnUtils only checks for a ../ substring, and does not validate the file type and spaceName parameter. | ||
| CVE-2018-17055 | Hig | 0.49 | 7.5 | 0.01 | Sep 28, 2018 | An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads. |
- risk 0.49cvss 7.5epss 0.01
ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.
- risk 0.49cvss 7.5epss 0.02
The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php.
- risk 0.49cvss 7.5epss 0.01
The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
- risk 0.49cvss 7.5epss 0.01
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
- risk 0.49cvss 7.5epss 0.01
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
- risk 0.49cvss 7.5epss 0.01
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
- risk 0.49cvss 7.5epss 0.01
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
- risk 0.49cvss 7.5epss 0.02
GoUrl.io GoURL Wordpress Plugin 1.4.13 and earlier is affected by: CWE-434. The impact is: unauthenticated/unzuthorized Attacker can upload executable file in website. The component is: gourl.php#L5637. The fixed version is: 1.4.14.
- risk 0.49cvss 7.5epss 0.01
MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and content. The component is: Filtering user parameters before passing them into phpthumb class. The attack vector is: web…
- risk 0.49cvss 7.5epss 0.02
A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions ), DIGSI 5 engineering software (All versions < V7.90), SIPROTEC 5 device types 6MD85, 6MD86, 6MD89, 7UM85,…
- risk 0.49cvss 7.5epss 0.01
The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.
- risk 0.49cvss 7.5epss 0.02
An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. The vulnerability could be exploited by an unauthenticated remote attacker to…
- risk 0.49cvss 7.5epss 0.02
Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archive and using the MoxieManager (for .NET) plugin before 2.1.4 in the moxiemanager directory within the installation folder…
- risk 0.49cvss 6.5epss 0.46
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).
- risk 0.49cvss 7.5epss 0.01
JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file.
- risk 0.49cvss 7.5epss 0.01
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=save&formzip=1 request with a ZIP archive that contains a file such as "1.jpg.php" (because input validation only checks that .jpg,…
- risk 0.49cvss 7.5epss 0.01
lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata parameters.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by entering a filename, directory name, and PHP code into the three text input fields.
- risk 0.49cvss 7.5epss 0.01
com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFileToFile method in CdnUtils only checks for a ../ substring, and does not validate the file type and spaceName parameter.
- risk 0.49cvss 7.5epss 0.01
An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.