CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,316)
page 159 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-6293 | Med | 0.42 | 6.5 | 0.01 | Aug 12, 2020 | SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other… | ||
| CVE-2020-14065 | Med | 0.42 | 6.5 | 0.01 | Jul 15, 2020 | IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space. | ||
| CVE-2020-1469 | Hig | 0.42 | 7.5 | 0.05 | Jul 14, 2020 | A denial of service vulnerability exists when the .NET implementation of Bond improperly parses input, aka 'Bond Denial of Service Vulnerability'. | ||
| CVE-2019-20897 | Med | 0.42 | 6.5 | 0.02 | Jul 13, 2020 | The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before… | ||
| CVE-2018-21243 | Med | 0.42 | 6.5 | 0.01 | Jun 4, 2020 | An issue was discovered in Foxit PhantomPDF before 8.3.6. It has COM object mishandling when Microsoft Word is used. | ||
| CVE-2020-9280 | Hig | 0.42 | 7.5 | 0.02 | Apr 15, 2020 | In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x.… | ||
| CVE-2020-9472 | Med | 0.42 | 6.5 | 0.02 | Mar 16, 2020 | Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality. | ||
| CVE-2020-5188 | Med | 0.42 | 6.5 | 0.02 | Feb 24, 2020 | DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions. | ||
| CVE-2019-11216 | Med | 0.42 | 6.5 | 0.02 | Dec 4, 2019 | BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are… | ||
| CVE-2019-17325 | Med | 0.42 | 6.5 | 0.01 | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. That could lead to disclosure of sensitive information. User interaction is required to exploit this vulnerability in that the… | ||
| CVE-2019-14916 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file upload. | ||
| CVE-2016-10959 | Med | 0.42 | 6.5 | 0.01 | Sep 16, 2019 | The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin-ajax.php. | ||
| CVE-2019-7861 | Hig | 0.42 | 7.5 | 0.02 | Aug 2, 2019 | Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. | ||
| CVE-2017-11561 | Med | 0.42 | 6.5 | 0.02 | May 23, 2019 | An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell. | ||
| CVE-2019-0017 | Med | 0.42 | 6.5 | 0.01 | Jan 15, 2019 | The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of malicious images or scripts, or other content types. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1. | ||
| CVE-2018-16097 | Med | 0.42 | 6.5 | 0.00 | Nov 30, 2018 | LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate. | ||
| CVE-2018-16093 | Med | 0.42 | 6.5 | 0.01 | Nov 30, 2018 | In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient sanitization during the upload of a backup file. | ||
| CVE-2018-2420 | Med | 0.42 | 6.5 | 0.01 | May 9, 2018 | SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation. | ||
| CVE-2017-6931 | Med | 0.42 | 6.5 | 0.01 | Mar 1, 2018 | In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If you have implemented a Settings Tray form in contrib or a custom module, the correct access checks… | ||
| CVE-2017-16594 | Med | 0.42 | 6.5 | 0.03 | Jan 23, 2018 | This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.… |
- risk 0.42cvss 6.5epss 0.01
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other…
- risk 0.42cvss 6.5epss 0.01
IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space.
- risk 0.42cvss 7.5epss 0.05
A denial of service vulnerability exists when the .NET implementation of Bond improperly parses input, aka 'Bond Denial of Service Vulnerability'.
- risk 0.42cvss 6.5epss 0.02
The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before…
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Foxit PhantomPDF before 8.3.6. It has COM object mishandling when Microsoft Word is used.
- risk 0.42cvss 7.5epss 0.02
In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x.…
- risk 0.42cvss 6.5epss 0.02
Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.
- risk 0.42cvss 6.5epss 0.02
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
- risk 0.42cvss 6.5epss 0.02
BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are…
- risk 0.42cvss 6.5epss 0.01
ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. That could lead to disclosure of sensitive information. User interaction is required to exploit this vulnerability in that the…
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file upload.
- risk 0.42cvss 6.5epss 0.01
The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin-ajax.php.
- risk 0.42cvss 7.5epss 0.02
Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
- risk 0.42cvss 6.5epss 0.02
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
- risk 0.42cvss 6.5epss 0.01
The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of malicious images or scripts, or other content types. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.
- risk 0.42cvss 6.5epss 0.00
LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate.
- risk 0.42cvss 6.5epss 0.01
In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient sanitization during the upload of a backup file.
- risk 0.42cvss 6.5epss 0.01
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.
- risk 0.42cvss 6.5epss 0.01
In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If you have implemented a Settings Tray form in contrib or a custom module, the correct access checks…
- risk 0.42cvss 6.5epss 0.03
This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.…