VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 54 of 216
  • CVE-2021-32089CriMay 11, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Zebra (formerly Motorola Solutions) Fixed RFID Reader FX9500 devices. An unauthenticated attacker can upload arbitrary files to the filesystem that can then be accessed through the web interface. This can lead to information disclosure and code…

  • CVE-2021-31737CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.04

    emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.

  • CVE-2021-24236CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.07

    The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along…

  • CVE-2020-19113CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.03

    Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.

  • CVE-2020-23083CriMay 3, 2021
    risk 0.64cvss 9.8epss 0.04

    Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload".

  • CVE-2020-21452CriApr 29, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in uniview ISC2500-S. This is an upload vulnerability where an attacker can upload malicious code via /Interface/DevManage/EC.php?cmd=upload

  • CVE-2021-24240CriApr 22, 2021
    risk 0.64cvss 9.8epss 0.03

    The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.

  • CVE-2020-29592CriApr 14, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Orchard before 1.10. A broken access control issue in Orchard components that use the TinyMCE HTML editor's file upload allows an attacker to upload dangerous executables that bypass the file types allowed (regardless of the file types allowed list in…

  • CVE-2021-24223CriApr 12, 2021
    risk 0.64cvss 9.8epss 0.02

    The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it's generated with md5(uniqid(rand())), however, in the case…

  • CVE-2021-24222CriApr 12, 2021
    risk 0.64cvss 9.8epss 0.02

    The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file…

  • CVE-2021-28173CriApr 6, 2021
    risk 0.64cvss 9.8epss 0.02

    The file upload function of Vangene deltaFlow E-platform does not perform access controlled properly. Remote attackers can upload and execute arbitrary files without login.

  • CVE-2021-24212CriApr 5, 2021
    risk 0.64cvss 9.8epss 0.08

    The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

  • CVE-2021-24171CriApr 5, 2021
    risk 0.64cvss 9.8epss 0.02

    The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "blocked" extension in the…

  • CVE-2020-21585CriApr 2, 2021
    risk 0.64cvss 9.8epss 0.03

    Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.

  • CVE-2021-27274CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.08

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MFileUploadController class.…

  • CVE-2021-28294CriMar 16, 2021
    risk 0.64cvss 9.8epss 0.04

    Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).

  • CVE-2021-27817CriMar 15, 2021
    risk 0.64cvss 9.8epss 0.03

    A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.

  • CVE-2021-26809CriFeb 17, 2021
    risk 0.64cvss 9.8epss 0.02

    PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.

  • CVE-2021-26918CriFeb 9, 2021
    risk 0.64cvss 9.8epss 0.03

    The ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send an image when a user joins the server" feature (or possibly have unspecified other impact) because the uploader web service allows double extensions (such as…

  • CVE-2020-20287CriFeb 1, 2021
    risk 0.64cvss 9.8epss 0.03

    Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.