VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,297)

page 5 of 215
  • CVE-2013-3684CriFeb 11, 2020
    risk 0.68cvss 9.8epss 0.19

    NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload

  • CVE-2013-2748CriJan 28, 2020
    risk 0.68cvss 9.8epss 0.13

    Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.

  • CVE-2019-13294CriJul 4, 2019
    risk 0.68cvss 9.8epss 0.19

    AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.

  • CVE-2018-17936CriNov 27, 2018
    risk 0.68cvss 9.8epss 0.15

    NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote code execution.

  • CVE-2015-9263CriAug 27, 2018
    risk 0.68cvss 9.8epss 0.12

    An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.

  • CVE-2018-15137CriAug 8, 2018
    risk 0.68cvss 9.8epss 0.18

    CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method.

  • CVE-2018-13981CriJul 16, 2018
    risk 0.68cvss 9.8epss 0.17

    The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default component that permits arbitrary upload of PHP files, because the formmailer widget blocks .php files but not .php5 or .phtml files.…

  • CVE-2018-0258CriMay 2, 2018
    risk 0.68cvss 9.8epss 0.49

    A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects the following…

  • CVE-2018-7665CriMar 5, 2018
    risk 0.68cvss 9.8epss 0.16

    An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter to actions/beats_uploader.php or actions/photo_uploader.php, or the coverPhoto parameter to edit_account.php.

  • CVE-2017-17976CriJan 26, 2018
    risk 0.68cvss 9.8epss 0.13

    In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.

  • CVE-2018-5724CriJan 16, 2018
    risk 0.68cvss 9.8epss 0.12

    MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi.

  • CVE-2017-16949CriDec 19, 2017
    risk 0.68cvss 9.8epss 0.19

    An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the attacker to override the settings for allowed file extensions and upload file size, related to inc/cores/file-uploader.php and…

  • CVE-2017-15580CriOct 23, 2017
    risk 0.68cvss 9.8epss 0.16

    osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a…

  • CVE-2015-2780CriOct 16, 2017
    risk 0.68cvss 9.8epss 0.15

    Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

  • CVE-2017-6090HigOct 3, 2017
    risk 0.68cvss 8.8epss 0.96

    Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/.

  • CVE-2017-1002008CriSep 14, 2017
    risk 0.68cvss 9.8epss 0.17

    Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.

  • CVE-2017-1002003CriSep 14, 2017
    risk 0.68cvss 9.8epss 0.12

    Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.

  • CVE-2017-1002002CriSep 14, 2017
    risk 0.68cvss 9.8epss 0.13

    Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/

  • CVE-2017-1002001CriSep 14, 2017
    risk 0.68cvss 9.8epss 0.11

    Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.

  • CVE-2026-32985CriMar 20, 2026
    risk 0.67cvss 9.8epss 0.01

    Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality that allows remote attackers to execute arbitrary code by uploading a crafted ZIP archive containing malicious PHP payloads.…