VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 149 of 216
  • CVE-2019-9613HigMar 6, 2019
    risk 0.47cvss 7.2epss 0.03

    An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadVideo URI.

  • CVE-2019-9572HigMar 5, 2019
    risk 0.47cvss 7.2epss 0.02

    SchoolCMS version 2.3.1 allows file upload via the theme upload feature at admin.php?m=admin&c=theme&a=upload by using the .zip extension along with the _Static substring, changing the Content-Type to application/zip, and placing PHP code after the ZIP header. This ultimately…

  • CVE-2019-9181HigFeb 26, 2019
    risk 0.47cvss 7.2epss 0.02

    SchoolCMS version 2.3.1 allows file upload via the logo upload feature at admin.php?m=admin&c=site&a=save by using the .jpg extension, changing the Content-Type to image/php, and placing PHP code after the JPEG data. This ultimately allows execution of arbitrary PHP code.

  • CVE-2019-9050HigFeb 23, 2019
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive, which is then extracted and executed.

  • CVE-2019-9042HigFeb 23, 2019
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in Sitemagic CMS v4.4. In the index.php?SMExt=SMFiles URI, the user can upload a .php file to execute arbitrary code, as demonstrated by 404.php. This can only occur if the administrator neglects to set FileExtensionFilter and there are untrusted user…

  • CVE-2018-19537HigNov 26, 2018
    risk 0.47cvss 7.2epss 0.06

    TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuration file that is encrypted with the 478DA50BF9E3D2CF key and uploaded through the web GUI by using the web admin account. The…

  • CVE-2018-19457HigNov 22, 2018
    risk 0.47cvss 7.2epss 0.04

    Logicspice FAQ Script 2.9.7 allows uploading arbitrary files, which leads to remote command execution via admin/faqs/faqimages with a .php file.

  • CVE-2018-19424HigNov 21, 2018
    risk 0.47cvss 7.2epss 0.02

    ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.

  • CVE-2018-18942HigNov 5, 2018
    risk 0.47cvss 7.2epss 0.02

    In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.

  • CVE-2018-14911HigAug 3, 2018
    risk 0.47cvss 7.2epss 0.01

    A file upload vulnerability exists in ukcms v1.1.7 and earlier. The vulnerability is due to the system not strictly filtering the file upload type. An attacker can exploit the vulnerability to upload a script Trojan to admin.php/admin/configset/index/group/upload.html to gain…

  • CVE-2018-11638HigJul 3, 2018
    risk 0.47cvss 7.2epss 0.04

    Unrestricted Upload of a File with a Dangerous Type in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to upload malicious code to the web root to gain code execution.

  • CVE-2018-13024HigJun 29, 2018
    risk 0.47cvss 7.2epss 0.01

    Metinfo v6.0.0 allows remote attackers to write code into a .php file, and execute that code, via the module parameter to admin/column/save.php in an editor upload action.

  • CVE-2018-13021HigJun 29, 2018
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code execution via the admin/index.php/template/upload URI.

  • CVE-2018-1265HigJun 6, 2018
    risk 0.47cvss 7.2epss 0.02

    Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps…

  • CVE-2018-11340HigMay 22, 2018
    risk 0.47cvss 7.2epss 0.02

    An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data to a specified filename. This can be used to place attacker controlled code on the file system that is then executed.

  • CVE-2018-11098HigMay 15, 2018
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/upload URI, a similar issue to CVE-2014-4912.

  • CVE-2018-9153HigApr 16, 2018
    risk 0.47cvss 7.2epss 0.01

    The plugin upload component in Z-BlogPHP 1.5.1 allows remote attackers to execute arbitrary PHP code via the app_id parameter to zb_users/plugin/AppCentre/plugin_edit.php because of an unanchored regular expression, a different vulnerability than CVE-2018-8893. The component…

  • CVE-2018-7567HigMar 4, 2018
    risk 0.47cvss 7.2epss 0.05

    In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are able to exploit a Blind Remote Code Execution vulnerability by loading a crafted opm file with an embedded CodeInstall element to execute a…

  • CVE-2017-9970HigFeb 12, 2018
    risk 0.47cvss 7.2epss 0.05

    A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains carefully crafted metadata allows for the file to be uploaded to any directory on the host machine information which could lead to…

  • CVE-2017-17987HigDec 30, 2017
    risk 0.47cvss 7.2epss 0.01

    PHP Scripts Mall Muslim Matrimonial Script allows arbitrary file upload via admin/mydetails_edit.php.