VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 52 of 222
  • CVE-2021-40883CriDec 14, 2021
    risk 0.64cvss 9.8epss 0.03

    A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.

  • CVE-2021-43117CriDec 13, 2021
    risk 0.64cvss 9.8epss 0.02

    fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.

  • CVE-2021-42125HigDec 7, 2021
    risk 0.64cvss 8.8epss 0.82

    An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.

  • CVE-2021-42099CriNov 30, 2021
    risk 0.64cvss 9.8epss 0.07

    Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.

  • CVE-2021-44093CriNov 28, 2021
    risk 0.64cvss 9.8epss 0.03

    A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell

  • CVE-2021-41833CriNov 11, 2021
    risk 0.64cvss 9.8epss 0.08

    Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.

  • CVE-2021-28023CriNov 8, 2021
    risk 0.64cvss 9.8epss 0.01

    Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by uploading a zip that extracts files in relative paths.

  • CVE-2020-18261CriNov 3, 2021
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.

  • CVE-2021-26740CriNov 1, 2021
    risk 0.64cvss 9.8epss 0.02

    Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code.

  • CVE-2021-41646CriOct 29, 2021
    risk 0.64cvss 9.8epss 0.07

    Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..

  • CVE-2021-41644CriOct 29, 2021
    risk 0.64cvss 9.8epss 0.03

    Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.

  • CVE-2021-41643CriOct 29, 2021
    risk 0.64cvss 9.8epss 0.05

    Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.

  • CVE-2021-36548CriOct 28, 2021
    risk 0.64cvss 9.8epss 0.03

    A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file.

  • CVE-2021-36547CriOct 28, 2021
    risk 0.64cvss 9.8epss 0.03

    A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file.

  • CVE-2021-20125CriOct 13, 2021
    risk 0.64cvss 9.8epss 0.04

    An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could leverage this vulnerability to upload files to any location on the target operating…

  • CVE-2021-41566CriOct 8, 2021
    risk 0.64cvss 9.8epss 0.02

    The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.

  • CVE-2021-37931CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37930CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37929CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37928CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.