VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 56 of 216
  • CVE-2020-12828CriMay 21, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path where a malicious executable file resides leads to executing the malicious…

  • CVE-2020-11817CriApr 27, 2020
    risk 0.64cvss 9.8epss 0.02

    In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs with the Maintenance Mode setting.

  • CVE-2020-10569CriApr 21, 2020
    risk 0.64cvss 9.8epss 0.03

    SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticated access to upload files, which can be used to execute commands on the system by chaining it with a GhostCat attack. NOTE: This…

  • CVE-2020-11815CriApr 16, 2020
    risk 0.64cvss 9.8epss 0.02

    In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs without the Maintenance Mode setting.

  • CVE-2020-11811CriApr 16, 2020
    risk 0.64cvss 9.8epss 0.03

    In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type value. After that, the attacker can execute an arbitrary command on the server using this malicious file.

  • CVE-2020-10507CriApr 15, 2020
    risk 0.64cvss 9.8epss 0.01

    The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Unrestricted file upload (RCE) , that would allow attackers to gain access in the hosting machine.

  • CVE-2020-10621CriApr 9, 2020
    risk 0.64cvss 9.8epss 0.02

    Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2).

  • CVE-2020-11598CriApr 6, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and executing an ASHX file.

  • CVE-2020-6008CriMar 31, 2020
    risk 0.64cvss 9.8epss 0.04

    LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution

  • CVE-2020-10964CriMar 25, 2020
    risk 0.64cvss 9.8epss 0.03

    Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.

  • CVE-2020-10806CriMar 22, 2020
    risk 0.64cvss 9.8epss 0.02

    eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration…

  • CVE-2020-9423CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.05

    LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. LogicalDoc provides a functionality to add documents. Those documents could then be used for multiple tasks, such as version control,…

  • CVE-2016-6918CriMar 9, 2020
    risk 0.64cvss 9.8epss 0.02

    Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (

  • CVE-2020-10225CriMar 8, 2020
    risk 0.64cvss 9.8epss 0.04

    An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command…

  • CVE-2020-10224CriMar 8, 2020
    risk 0.64cvss 9.8epss 0.05

    An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command…

  • CVE-2020-9380CriMar 5, 2020
    risk 0.64cvss 9.8epss 0.04

    IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script.

  • CVE-2013-2057CriFeb 11, 2020
    risk 0.64cvss 9.8epss 0.02

    YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability

  • CVE-2019-20451CriFeb 10, 2020
    risk 0.64cvss 9.8epss 0.08

    The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and requesting /REBOOTSYSTEM or /RESTARTVNC. (Authentication is required but an XML file containing credentials can be downloaded.)

  • CVE-2013-3591HigFeb 7, 2020
    risk 0.64cvss 8.8epss 0.43

    vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability

  • CVE-2014-2025CriJan 31, 2020
    risk 0.64cvss 9.8epss 0.04

    Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension,…