VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 148 of 216
  • CVE-2011-2933HigJan 14, 2020
    risk 0.47cvss 7.2epss 0.01

    An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files with .htaccess, .php4, .php5, and .phtl extensions.

  • CVE-2019-20183HigJan 9, 2020
    risk 0.47cvss 7.2epss 0.08

    uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the client side. The attacker can modify global.js to allow the .php extension.

  • CVE-2019-20048HigDec 27, 2019
    risk 0.47cvss 7.2epss 0.06

    An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with elevated privileges in the Web Directory component on port 389, may upload a PHP file to achieve Remote Code Execution as SYSTEM.

  • CVE-2019-19020HigDec 2, 2019
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a crafted backup file that enables an attacker to execute arbitrary code by overwriting existing files or adding new PHP files under the web root. This requires…

  • CVE-2019-11021HigOct 24, 2019
    risk 0.47cvss 7.2epss 0.02

    admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execution. NOTE: "While inadvertently allowing a PHP file to be uploaded via Media Manager was an oversight, it still requires an admin permission. We think it's…

  • CVE-2019-16530HigOct 21, 2019
    risk 0.47cvss 7.2epss 0.03

    Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.

  • CVE-2019-17188HigOct 4, 2019
    risk 0.47cvss 7.2epss 0.01

    An unrestricted file upload vulnerability was discovered in catalog/productinfo/imageupload in Fecshop FecMall 2.3.4. An attacker can bypass a front-end restriction and upload PHP code to the webserver, by providing image data and the image/jpeg content type, with a .php…

  • CVE-2019-17046HigSep 30, 2019
    risk 0.47cvss 7.2epss 0.04

    Ilch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settings/index page.

  • CVE-2019-14252HigSep 18, 2019
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in the secure portal in Publisure 2.1.2. Once successfully authenticated as an administrator, one is able to inject arbitrary PHP code by using the adminCons.php form. The code is then stored in the E:\PUBLISURE\webservice\webpages\AdminDir\Templates\…

  • CVE-2019-8371HigSep 16, 2019
    risk 0.47cvss 7.2epss 0.03

    OpenEMR v5.0.1-6 allows code execution.

  • CVE-2018-18572HigAug 22, 2019
    risk 0.47cvss 7.2epss 0.03

    osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP-related extensions (such as .phtml and .php5) didn't execute in the application. But this filter didn't prevent the '.pht'…

  • CVE-2019-3960HigJul 31, 2019
    risk 0.47cvss 7.2epss 0.03

    Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uploading a malicious PHP file.

  • CVE-2019-12326HigJul 22, 2019
    risk 0.47cvss 7.2epss 0.03

    Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated ringtone file, with an executable payload (shell commands within the file) and trigger code execution.

  • CVE-2019-10935HigJul 11, 2019
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd 11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC…

  • CVE-2019-0327HigJul 10, 2019
    risk 0.47cvss 7.2epss 0.02

    SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.31, 7.4, 7.5), allows an attacker to upload files (including script files) without proper file format validation.

  • CVE-2019-9842HigJun 14, 2019
    risk 0.47cvss 7.2epss 0.02

    madskristensen MiniBlog through 2018-05-18 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in app_code/handlers/PostHandler.cs writes a decoded base64 string to a file without validating the extension.

  • CVE-2019-1861HigJun 5, 2019
    risk 0.47cvss 7.2epss 0.04

    A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of files uploaded to the affected application. An attacker could exploit…

  • CVE-2016-10751HigMay 24, 2019
    risk 0.47cvss 7.2epss 0.03

    osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?page=ajax&action=ajax_upload.

  • CVE-2019-10478HigApr 5, 2019
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. An unrestricted file upload vulnerability in the Front Circle Controller glytoolcgi/settingfile_upload.cgi allows attackers to upload supplied data. This can be used to place attacker controlled…

  • CVE-2018-17418HigMar 7, 2019
    risk 0.47cvss 7.2epss 0.03

    Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the forbidden_types variable.