VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,297)

page 214 of 215
  • CVE-2020-26295HigJan 21, 2021
    risk 0.00cvss 8.7epss 0.02

    OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator with permission to import/export data and to edit cms pages was able to inject an executable file on the server via layout xml. The latest OpenMage Versions…

  • CVE-2020-26285HigJan 21, 2021
    risk 0.00cvss 8.7epss 0.03

    OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerability which enables remote code execution. In affected versions an administrator with permission to import/export data and to create widget instances was…

  • CVE-2020-26252HigJan 20, 2021
    risk 0.00cvss 8.7epss 0.02

    OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerability which enables remote code execution. In affected versions an administrator with permission to update product data to be able to store an executable…

  • CVE-2021-21245CriJan 15, 2021
    risk 0.00cvss 10.0epss 0.01

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location (`request.getHeader("File-Name")`). This issue may lead to arbitrary file upload which can…

  • CVE-2020-26286HigDec 29, 2020
    risk 0.00cvss 7.5epss 0.01

    HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an unauthenticated attacker can upload arbitrary files to the upload storage backend including HTML, JS and PHP files. The problem is patched in HedgeDoc 1.7.1. You should…

  • CVE-2020-15189MedSep 18, 2020
    risk 0.00cvss 6.8epss 0.03

    SOY CMS 3.0.2 and earlier is affected by Remote Code Execution (RCE) using Unrestricted File Upload. Cross-Site Scripting(XSS) vulnerability that was used in CVE-2020-15183 can be used to increase impact by redirecting the administrator to access a specially crafted page. This…

  • CVE-2020-14961MedJun 22, 2020
    risk 0.00cvss 5.3epss 0.01

    Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.

  • CVE-2020-14067CriJun 15, 2020
    risk 0.00cvss 9.8epss 0.01

    The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may contain PHP code, in check_upload in lib/packages/extensions/extension.class.php and lib/packages/themes/theme.class.php.

  • CVE-2020-11011CriApr 22, 2020
    risk 0.00cvss 9.9epss 0.02

    In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arbitrary code. This is patched in version 1.7.8.

  • CVE-2020-11722CriApr 12, 2020
    risk 0.00cvss 9.8epss 0.04

    Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.

  • CVE-2020-10562HigMar 13, 2020
    risk 0.00cvss 7.2epss 0.01

    An issue was discovered in DEVOME GRR before 3.4.1c. admin_edit_room.php mishandles file uploads.

  • CVE-2019-16790MedDec 30, 2019
    risk 0.00cvss 6.5epss 0.01

    In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.

  • CVE-2019-17536MedOct 13, 2019
    risk 0.00cvss 4.9epss 0.02

    Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/controllers/fm.php. The attacker needs to use admin/media_upload and fm/move.

  • CVE-2018-21024CriOct 8, 2019
    risk 0.00cvss 9.8epss 0.02

    licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.

  • CVE-2019-1010062CriJul 16, 2019
    risk 0.00cvss 9.8epss 0.02

    PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type. The impact is: get webshell. The component is: data/inc/images.php line36. The attack vector is: modify the MIME TYPE on HTTP request to upload a php file. The fixed version is:…

  • CVE-2019-13464HigJul 9, 2019
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.

  • CVE-2019-12548HigJun 3, 2019
    risk 0.00cvss 8.8epss 0.03

    Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/ajax/upload-logo.

  • CVE-2019-9185HigMar 7, 2019
    risk 0.00cvss 8.8epss 0.03

    Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension.

  • CVE-2018-16388HigSep 12, 2018
    risk 0.00cvss 7.2epss 0.02

    e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php filename with the image/jpeg content type.

  • CVE-2018-1000658HigSep 6, 2018
    risk 0.00cvss 8.8epss 0.02

    LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution via webshell. This attack appear to be exploitable via an authenticated user uploading a zip archive which can contains malicious…