VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 56 of 222
  • CVE-2021-24240CriApr 22, 2021
    risk 0.64cvss 9.8epss 0.03

    The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.

  • CVE-2020-29592CriApr 14, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Orchard before 1.10. A broken access control issue in Orchard components that use the TinyMCE HTML editor's file upload allows an attacker to upload dangerous executables that bypass the file types allowed (regardless of the file types allowed list in…

  • CVE-2021-24223CriApr 12, 2021
    risk 0.64cvss 9.8epss 0.02

    The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it's generated with md5(uniqid(rand())), however, in the case…

  • CVE-2021-24222CriApr 12, 2021
    risk 0.64cvss 9.8epss 0.02

    The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file…

  • CVE-2021-28173CriApr 6, 2021
    risk 0.64cvss 9.8epss 0.02

    The file upload function of Vangene deltaFlow E-platform does not perform access controlled properly. Remote attackers can upload and execute arbitrary files without login.

  • CVE-2021-24212CriApr 5, 2021
    risk 0.64cvss 9.8epss 0.08

    The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

  • CVE-2021-24171CriApr 5, 2021
    risk 0.64cvss 9.8epss 0.02

    The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "blocked" extension in the…

  • CVE-2020-21585CriApr 2, 2021
    risk 0.64cvss 9.8epss 0.03

    Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.

  • CVE-2021-27274CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.08

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MFileUploadController class.…

  • CVE-2021-28294CriMar 16, 2021
    risk 0.64cvss 9.8epss 0.04

    Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).

  • CVE-2021-27817CriMar 15, 2021
    risk 0.64cvss 9.8epss 0.03

    A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.

  • CVE-2021-26809CriFeb 17, 2021
    risk 0.64cvss 9.8epss 0.02

    PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.

  • CVE-2021-26918CriFeb 9, 2021
    risk 0.64cvss 9.8epss 0.03

    The ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send an image when a user joins the server" feature (or possibly have unspecified other impact) because the uploader web service allows double extensions (such as…

  • CVE-2020-20287CriFeb 1, 2021
    risk 0.64cvss 9.8epss 0.03

    Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.

  • CVE-2019-18643CriJan 7, 2021
    risk 0.64cvss 9.8epss 0.04

    Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklist that can be bypassed by adding multiple spaces and periods after the file name. This could allow…

  • CVE-2020-35797CriDec 30, 2020
    risk 0.64cvss 9.8epss 0.02

    NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an unauthenticated attacker.

  • CVE-2020-25010CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.03

    An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to upload a malicious script file by constructing a POST type request and writing a payload in the request…

  • CVE-2020-25537CriNov 30, 2020
    risk 0.64cvss 9.8epss 0.02

    File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.

  • CVE-2020-28130CriNov 17, 2020
    risk 0.64cvss 9.8epss 0.07

    An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code execution via admin/borrower/index.php?view=add because .php files can be uploaded to admin/borrower/photos (under the web root).

  • CVE-2020-26553CriNov 17, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.