VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 158 of 216
  • CVE-2023-28652MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.01

    An authenticated malicious user could successfully upload a malicious image could lead to a denial-of-service condition.

  • CVE-2023-20009MedMar 1, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The…

  • CVE-2023-24045MedMar 1, 2023
    risk 0.42cvss 6.5epss 0.01

    In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.

  • CVE-2022-40217MedSep 21, 2022
    risk 0.42cvss 6.5epss 0.01

    Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.

  • CVE-2015-1785MedJul 7, 2022
    risk 0.42cvss 6.5epss 0.01

    In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing…

  • CVE-2017-20021MedJun 9, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version…

  • CVE-2022-22482MedMay 17, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenticated user to upload files that could fill up the filesystem and cause a denial of service. IBM X-Force ID: 225977.

  • CVE-2021-24947MedFeb 7, 2022
    risk 0.42cvss 6.5epss 0.03

    The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server

  • CVE-2021-39222MedNov 15, 2021
    risk 0.42cvss 6.4epss 0.01

    Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user would need to right-click on a malicious file and open the file in a new tab. Due the…

  • CVE-2020-20691MedSep 27, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafted HTML files.

  • CVE-2021-33884MedAug 25, 2021
    risk 0.42cvss 6.5epss 0.01

    An Unrestricted Upload of File with Dangerous Type vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows remote attackers to upload any files to the /tmp directory of the device through the webpage API. This can result in critical files being overwritten.

  • CVE-2020-21005MedJun 3, 2021
    risk 0.42cvss 6.5epss 0.01

    WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is controllable, the user can modify the upload file type to get webshell.

  • CVE-2021-31542HigMay 5, 2021
    risk 0.42cvss 7.5epss 0.05

    In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.

  • CVE-2021-30209MedApr 15, 2021
    risk 0.42cvss 6.5epss 0.01

    Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security verification, which may lead to obtaining system permissions.

  • CVE-2021-26597MedMar 25, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction…

  • CVE-2021-21351MedMar 23, 2021
    risk 0.42cvss 5.4epss 0.82

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is…

  • CVE-2020-29450MedJan 19, 2021
    risk 0.42cvss 6.5epss 0.02

    Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature. The affected versions are before version 7.2.0.

  • CVE-2020-26828MedDec 9, 2020
    risk 0.42cvss 6.4epss 0.01

    SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of specific file type. In some file types it is possible to enter formulas which can call external applications or execute scripts. The execution of a payload…

  • CVE-2020-26826MedDec 9, 2020
    risk 0.42cvss 6.5epss 0.01

    Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upload.

  • CVE-2020-15839MedSep 22, 2020
    risk 0.42cvss 6.5epss 0.02

    Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.