VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 55 of 216
  • CVE-2019-18643CriJan 7, 2021
    risk 0.64cvss 9.8epss 0.04

    Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklist that can be bypassed by adding multiple spaces and periods after the file name. This could allow…

  • CVE-2020-35797CriDec 30, 2020
    risk 0.64cvss 9.8epss 0.02

    NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an unauthenticated attacker.

  • CVE-2020-25010CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to upload a malicious script file by constructing a POST type request and writing a payload in the request…

  • CVE-2020-25537CriNov 30, 2020
    risk 0.64cvss 9.8epss 0.02

    File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.

  • CVE-2020-28130CriNov 17, 2020
    risk 0.64cvss 9.8epss 0.07

    An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code execution via admin/borrower/index.php?view=add because .php files can be uploaded to admin/borrower/photos (under the web root).

  • CVE-2020-26553CriNov 17, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.

  • CVE-2020-28140CriNov 17, 2020
    risk 0.64cvss 9.8epss 0.02

    SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Products.php.

  • CVE-2020-23138CriNov 9, 2020
    risk 0.64cvss 9.8epss 0.01

    An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.

  • CVE-2020-11486CriOct 29, 2020
    risk 0.64cvss 9.8epss 0.03

    NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software allows an attacker to upload or transfer files that can be automatically processed within the product's environment, which may lead to…

  • CVE-2020-27956CriOct 28, 2020
    risk 0.64cvss 9.8epss 0.05

    An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execution via admin/index.php?page=manage_car because .php files can be uploaded to admin/assets/uploads/ (under the web root).

  • CVE-2020-25483CriOct 23, 2020
    risk 0.64cvss 9.8epss 0.09

    An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.

  • CVE-2020-25763CriSep 30, 2020
    risk 0.64cvss 9.8epss 0.05

    Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files.

  • CVE-2020-19672CriSep 30, 2020
    risk 0.64cvss 9.8epss 0.01

    Niushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface, through parameter upload, bypass the getimagesize function, upload php file, getshell.

  • CVE-2020-12843CriSep 24, 2020
    risk 0.64cvss 9.8epss 0.01

    ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magic bytes for WAV must be used.

  • CVE-2020-23828CriSep 15, 2020
    risk 0.64cvss 9.8epss 0.04

    A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution (RCE) on the hosting webserver by uploading a crafted PHP web-shell that bypasses the image upload filters. An attack uses…

  • CVE-2020-24199CriSep 9, 2020
    risk 0.64cvss 9.8epss 0.04

    Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.

  • CVE-2020-24203CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.04

    Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution.

  • CVE-2020-24202CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.03

    File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution.

  • CVE-2018-21244CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows arbitrary application execution via an embedded executable file in a PDF portfolio, aka FG-VD-18-029.

  • CVE-2020-13442CriMay 25, 2020
    risk 0.64cvss 9.8epss 0.03

    A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.