CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,314)
page 58 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-10955 | Cri | 0.64 | 9.8 | 0.02 | Sep 13, 2019 | The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking. | ||
| CVE-2016-10954 | Cri | 0.64 | 9.8 | 0.02 | Sep 13, 2019 | The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload. | ||
| CVE-2019-16192 | Cri | 0.64 | 9.8 | 0.02 | Sep 9, 2019 | upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbitrary PHP code through module management files, as demonstrated by a .php file in a ZIP archive. | ||
| CVE-2019-13187 | Cri | 0.64 | 9.8 | 0.02 | Sep 5, 2019 | The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php. | ||
| CVE-2019-13976 | Cri | 0.64 | 9.8 | 0.02 | Sep 4, 2019 | eGain Chat 15.0.3 allows unrestricted file upload. | ||
| CVE-2019-15524 | Cri | 0.64 | 9.8 | 0.03 | Aug 26, 2019 | CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote code execution by visiting a photo/upload/2019/ URI. | ||
| CVE-2019-11031 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, and then execute these files with SYSTEM privileges. | ||
| CVE-2019-15091 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload. | ||
| CVE-2019-13973 | Cri | 0.64 | 9.8 | 0.02 | Jul 19, 2019 | LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used. | ||
| CVE-2019-12803 | Cri | 0.64 | 9.8 | 0.02 | Jul 10, 2019 | In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell upload, an attacker can use the webshell to perform remote code exection such as… | ||
| CVE-2019-12971 | Cri | 0.64 | 9.8 | 0.02 | Jul 5, 2019 | BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type. | ||
| CVE-2019-13082 | Cri | 0.64 | 9.8 | 0.04 | Jun 30, 2019 | Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This means that by putting a .php… | ||
| CVE-2019-9642 | Cri | 0.64 | 9.8 | 0.02 | Jun 5, 2019 | An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourth line of a .php file, as demonstrated by a PoC.php created by the guest account, with execution… | ||
| CVE-2019-11185 | Cri | 0.64 | 9.8 | 0.04 | Jun 3, 2019 | The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted executable file extension in conjunction with… | ||
| CVE-2019-12377 | Cri | 0.64 | 9.8 | 0.06 | Jun 3, 2019 | A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution. | ||
| CVE-2016-10752 | Cri | 0.64 | 9.8 | 0.02 | May 24, 2019 | serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename. | ||
| CVE-2019-12150 | Cri | 0.64 | 9.8 | 0.02 | May 24, 2019 | Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under the UltimateEditorInclude/UserFiles/ URI. | ||
| CVE-2019-11887 | Cri | 0.64 | 9.8 | 0.02 | May 17, 2019 | SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution. | ||
| CVE-2019-9951 | Cri | 0.64 | 9.8 | 0.02 | Apr 24, 2019 | Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page… | ||
| CVE-2019-11447 | Hig | 0.64 | 8.8 | 0.52 | Apr 22, 2019 | An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php.… |
- risk 0.64cvss 9.8epss 0.02
The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.
- risk 0.64cvss 9.8epss 0.02
The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.
- risk 0.64cvss 9.8epss 0.02
upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbitrary PHP code through module management files, as demonstrated by a .php file in a ZIP archive.
- risk 0.64cvss 9.8epss 0.02
The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php.
- risk 0.64cvss 9.8epss 0.02
eGain Chat 15.0.3 allows unrestricted file upload.
- risk 0.64cvss 9.8epss 0.03
CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote code execution by visiting a photo/upload/2019/ URI.
- risk 0.64cvss 9.8epss 0.02
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, and then execute these files with SYSTEM privileges.
- risk 0.64cvss 9.8epss 0.02
filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.
- risk 0.64cvss 9.8epss 0.02
LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used.
- risk 0.64cvss 9.8epss 0.02
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell upload, an attacker can use the webshell to perform remote code exection such as…
- risk 0.64cvss 9.8epss 0.02
BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type.
- risk 0.64cvss 9.8epss 0.04
Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This means that by putting a .php…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourth line of a .php file, as demonstrated by a PoC.php created by the guest account, with execution…
- risk 0.64cvss 9.8epss 0.04
The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted executable file extension in conjunction with…
- risk 0.64cvss 9.8epss 0.06
A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution.
- risk 0.64cvss 9.8epss 0.02
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename.
- risk 0.64cvss 9.8epss 0.02
Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under the UltimateEditorInclude/UserFiles/ URI.
- risk 0.64cvss 9.8epss 0.02
SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution.
- risk 0.64cvss 9.8epss 0.02
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page…
- risk 0.64cvss 8.8epss 0.52
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php.…