VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 53 of 222
  • CVE-2021-37762CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.08

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.

  • CVE-2021-3832CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.02

    Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in order to exploit the vulnerability.

  • CVE-2021-41290CriSep 30, 2021
    risk 0.64cvss 9.8epss 0.02

    ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected…

  • CVE-2021-37761CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.

  • CVE-2021-26794CriSep 23, 2021
    risk 0.64cvss 9.8epss 0.02

    Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.

  • CVE-2021-36582CriSep 14, 2021
    risk 0.64cvss 9.8epss 0.01

    In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and can be simply triggered by browsing that URL.

  • CVE-2021-36581CriSep 14, 2021
    risk 0.64cvss 9.8epss 0.01

    Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

  • CVE-2021-24493CriSep 13, 2021
    risk 0.64cvss 9.8epss 0.02

    The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authenticated user does not have any security measure in place to prevent upload of malicious files, such as PHP, allowing unauthenticated users to upload arbitrary…

  • CVE-2020-19267CriSep 9, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2020-19138CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.06

    Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src/main/java/com/dotmarketing/filters/CMSFilter.java".

  • CVE-2021-40175CriAug 29, 2021
    risk 0.64cvss 9.8epss 0.07

    Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.

  • CVE-2020-18114CriAug 27, 2021
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.

  • CVE-2021-38613CriAug 24, 2021
    risk 0.64cvss 9.8epss 0.05

    The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any code to the target system and achieve remote code execution.

  • CVE-2020-18879CriAug 20, 2021
    risk 0.64cvss 9.8epss 0.03

    Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.

  • CVE-2021-37608CriAug 18, 2021
    risk 0.64cvss 9.8epss 0.06

    Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at…

  • CVE-2020-18704CriAug 16, 2021
    risk 0.64cvss 9.8epss 0.03

    Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in the component 'Change Widgy Page'.

  • CVE-2021-38753CriAug 16, 2021
    risk 0.64cvss 9.8epss 0.01

    An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app.

  • CVE-2021-29377CriAug 12, 2021
    risk 0.64cvss 9.8epss 0.02

    Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can be uploaded via admin.php/index/upload because app/common/service/UploadService.php mishandles fileExt.

  • CVE-2020-20979CriAug 12, 2021
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code.

  • CVE-2020-28165CriAug 12, 2021
    risk 0.64cvss 9.8epss 0.01

    The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function.