VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 146 of 216
  • CVE-2021-40188HigOct 11, 2021
    risk 0.47cvss 7.2epss 0.01

    PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions such as ".php, .php7, .phtml, .php5, ...". An attacker can upload a malicious file and execute code on the server.

  • CVE-2021-40324HigOct 4, 2021
    risk 0.47cvss 7.5epss 0.69

    Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

  • CVE-2021-24663HigSep 20, 2021
    risk 0.47cvss 7.2epss 0.01

    The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that are indeed images, allowing high privilege users such as admin to upload arbitrary file like PHP, leading to RCE

  • CVE-2020-21483HigSep 15, 2021
    risk 0.47cvss 7.2epss 0.02

    An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file which is later changed to a PHP file.

  • CVE-2020-21481HigSep 15, 2021
    risk 0.47cvss 7.2epss 0.02

    An arbitrary file upload vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted .txt file which is later changed to a PHP file.

  • CVE-2020-18886HigAug 20, 2021
    risk 0.47cvss 7.2epss 0.02

    Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.

  • CVE-2021-22937HigAug 16, 2021
    risk 0.47cvss 7.2epss 0.08

    A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.

  • CVE-2020-18462HigAug 12, 2021
    risk 0.47cvss 7.2epss 0.01

    File Upload vulnerabilty in AikCms v2.0.0 in poster_edit.php because the background file management office does not verify the uploaded file.

  • CVE-2021-23394HigJun 13, 2021
    risk 0.47cvss 8.1epss 0.19

    The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.

  • CVE-2020-23765HigMay 21, 2021
    risk 0.47cvss 7.2epss 0.01

    A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe plugins to upload a backup file and control the server.

  • CVE-2021-24254HigMay 6, 2021
    risk 0.47cvss 7.2epss 0.02

    The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.

  • CVE-2021-24252HigMay 6, 2021
    risk 0.47cvss 7.2epss 0.02

    The Event Banner WordPress plugin through 1.3 does not verify the uploaded image file, allowing admin accounts to upload arbitrary files, such as .exe, .php, or others executable, leading to RCE. Due to the lack of CSRF check, the issue can also be used via such vector to…

  • CVE-2021-24248HigMay 6, 2021
    risk 0.47cvss 7.2epss 0.02

    The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example,…

  • CVE-2020-28173HigMar 31, 2021
    risk 0.47cvss 7.2epss 0.03

    Simple College Website 1.0 allows a user to conduct remote code execution via /alumni/admin/ajax.php?action=save_settings when uploading a malicious file using the image upload functionality, which is stored in /alumni/admin/assets/uploads/.

  • CVE-2021-24123HigMar 18, 2021
    risk 0.47cvss 7.2epss 0.02

    Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading…

  • CVE-2020-36079HigFeb 26, 2021
    risk 0.47cvss 7.2epss 0.05

    Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder box, and then drag and drop files into the Files(elFinder) portion of the UI. This can, for example,…

  • CVE-2021-25780HigFeb 17, 2021
    risk 0.47cvss 7.2epss 0.02

    An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote attacker to upload content to the server, including PHP files, which could result in command execution and obtaining a shell.

  • CVE-2020-22643HigJan 26, 2021
    risk 0.47cvss 7.2epss 0.02

    Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in, open the administrator image upload page to potentially upload malicious files.

  • CVE-2020-35657HigDec 23, 2020
    risk 0.47cvss 7.2epss 0.02

    Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing a .php file that is able to execute OS commands. NOTE: this is unrelated to the JAWS (aka Job Access With Speech)…

  • CVE-2020-35656HigDec 23, 2020
    risk 0.47cvss 7.2epss 0.02

    Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadget&comp=FileBrowser and admin.php?reqGadget=FileBrowser&reqAction=Files to upload a .php file. NOTE: this is unrelated…