VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 147 of 216
  • CVE-2020-28072HigDec 15, 2020
    risk 0.47cvss 7.2epss 0.03

    A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.

  • CVE-2020-23520HigDec 9, 2020
    risk 0.47cvss 7.2epss 0.02

    imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.

  • CVE-2020-28939HigDec 3, 2020
    risk 0.47cvss 7.2epss 0.02

    OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious files, such as PHP web shells, which can lead to arbitrary code execution on the…

  • CVE-2020-29441HigNov 30, 2020
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker can upload arbitrary files. In some cases, this attack may consume the available database space (Denial of Service), corrupt legitimate data if files are being…

  • CVE-2020-28692HigNov 16, 2020
    risk 0.47cvss 7.2epss 0.02

    In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files.

  • CVE-2020-26820HigNov 10, 2020
    risk 0.47cvss 7.2epss 0.04

    SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then…

  • CVE-2019-1888HigSep 23, 2020
    risk 0.47cvss 7.2epss 0.03

    A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to upload arbitrary files and execute commands on the underlying operating system. To exploit this vulnerability, an attacker…

  • CVE-2020-25287HigSep 13, 2020
    risk 0.47cvss 7.2epss 0.03

    Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any file, as demonstrated by an admin/admin_editor.php the_file=..%2Findex.php&open=Open request.

  • CVE-2020-24986HigSep 4, 2020
    risk 0.47cvss 7.2epss 0.02

    Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands.

  • CVE-2020-24196HigAug 27, 2020
    risk 0.47cvss 7.2epss 0.03

    An Arbitrary File Upload in Vehicle Image Upload in Online Bike Rental v1.0 allows authenticated admin to conduct remote code execution.

  • CVE-2020-17452HigAug 9, 2020
    risk 0.47cvss 7.2epss 0.02

    flatCore before 1.5.7 allows upload and execution of a .php file by an admin.

  • CVE-2019-15123HigJun 12, 2020
    risk 0.47cvss 7.2epss 0.02

    The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Remote Code Execution on the site.

  • CVE-2020-11544HigApr 6, 2020
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account because the upload section on the file-manager page contains an arbitrary file upload vulnerability via add_cars.php. There are no…

  • CVE-2020-11451HigApr 2, 2020
    risk 0.47cvss 7.2epss 0.03

    The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files with arbitrary extensions and data. (This is also exploitable via SSRF). Note: The ability to upload visualization plugins requires…

  • CVE-2020-10934HigMar 24, 2020
    risk 0.47cvss 7.2epss 0.01

    Acyba AcyMailing before 6.9.2 mishandles file uploads by admins.

  • CVE-2020-8511HigMar 23, 2020
    risk 0.47cvss 7.2epss 0.03

    In Artica Pandora FMS through 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the File Repository component, a different issue than CVE-2020-7935 and CVE-2020-8500.

  • CVE-2020-7935HigMar 23, 2020
    risk 0.47cvss 7.2epss 0.03

    Artica Pandora FMS through 7.42 is vulnerable to remote PHP code execution because of an Unrestricted Upload Of A File With A Dangerous Type issue in the File Manager. An attacker can create a (or use an existing) directory that is externally accessible to store PHP files. The…

  • CVE-2019-11074HigMar 17, 2020
    risk 0.47cvss 7.2epss 0.05

    A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attackers to place files in arbitrary locations with SYSTEM privileges (although not controlling the contents of such files) due to insufficient sanitisation when…

  • CVE-2020-8500HigMar 2, 2020
    risk 0.47cvss 7.2epss 0.04

    In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality

  • CVE-2019-16514HigJan 23, 2020
    risk 0.47cvss 7.2epss 0.04

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administrative users could upload an unsigned extension ZIP file containing executable code that is subsequently executed by the server.