VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 51 of 216
  • CVE-2021-20125CriOct 13, 2021
    risk 0.64cvss 9.8epss 0.04

    An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could leverage this vulnerability to upload files to any location on the target operating…

  • CVE-2021-41566CriOct 8, 2021
    risk 0.64cvss 9.8epss 0.02

    The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.

  • CVE-2021-37931CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37930CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37929CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37928CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37762CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.08

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.

  • CVE-2021-3832CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.02

    Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in order to exploit the vulnerability.

  • CVE-2021-41290CriSep 30, 2021
    risk 0.64cvss 9.8epss 0.02

    ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected…

  • CVE-2021-37761CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.

  • CVE-2021-26794CriSep 23, 2021
    risk 0.64cvss 9.8epss 0.02

    Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.

  • CVE-2021-36582CriSep 14, 2021
    risk 0.64cvss 9.8epss 0.01

    In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and can be simply triggered by browsing that URL.

  • CVE-2021-36581CriSep 14, 2021
    risk 0.64cvss 9.8epss 0.01

    Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

  • CVE-2021-24493CriSep 13, 2021
    risk 0.64cvss 9.8epss 0.02

    The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authenticated user does not have any security measure in place to prevent upload of malicious files, such as PHP, allowing unauthenticated users to upload arbitrary…

  • CVE-2020-19267CriSep 9, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2020-19138CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.06

    Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src/main/java/com/dotmarketing/filters/CMSFilter.java".

  • CVE-2021-40175CriAug 29, 2021
    risk 0.64cvss 9.8epss 0.07

    Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.

  • CVE-2020-18114CriAug 27, 2021
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.

  • CVE-2021-38613CriAug 24, 2021
    risk 0.64cvss 9.8epss 0.05

    The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any code to the target system and achieve remote code execution.

  • CVE-2020-18879CriAug 20, 2021
    risk 0.64cvss 9.8epss 0.03

    Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.