VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 58 of 216
  • CVE-2016-10955CriSep 13, 2019
    risk 0.64cvss 9.8epss 0.02

    The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.

  • CVE-2016-10954CriSep 13, 2019
    risk 0.64cvss 9.8epss 0.02

    The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.

  • CVE-2019-16192CriSep 9, 2019
    risk 0.64cvss 9.8epss 0.02

    upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbitrary PHP code through module management files, as demonstrated by a .php file in a ZIP archive.

  • CVE-2019-13187CriSep 5, 2019
    risk 0.64cvss 9.8epss 0.02

    The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php.

  • CVE-2019-13976CriSep 4, 2019
    risk 0.64cvss 9.8epss 0.02

    eGain Chat 15.0.3 allows unrestricted file upload.

  • CVE-2019-15524CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.03

    CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote code execution by visiting a photo/upload/2019/ URI.

  • CVE-2019-11031CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, and then execute these files with SYSTEM privileges.

  • CVE-2019-15091CriAug 16, 2019
    risk 0.64cvss 9.8epss 0.02

    filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.

  • CVE-2019-13973CriJul 19, 2019
    risk 0.64cvss 9.8epss 0.02

    LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used.

  • CVE-2019-12803CriJul 10, 2019
    risk 0.64cvss 9.8epss 0.02

    In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell upload, an attacker can use the webshell to perform remote code exection such as…

  • CVE-2019-12971CriJul 5, 2019
    risk 0.64cvss 9.8epss 0.02

    BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type.

  • CVE-2019-13082CriJun 30, 2019
    risk 0.64cvss 9.8epss 0.04

    Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This means that by putting a .php…

  • CVE-2019-9642CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourth line of a .php file, as demonstrated by a PoC.php created by the guest account, with execution…

  • CVE-2019-11185CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.04

    The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted executable file extension in conjunction with…

  • CVE-2019-12377CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.06

    A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution.

  • CVE-2016-10752CriMay 24, 2019
    risk 0.64cvss 9.8epss 0.02

    serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename.

  • CVE-2019-12150CriMay 24, 2019
    risk 0.64cvss 9.8epss 0.02

    Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under the UltimateEditorInclude/UserFiles/ URI.

  • CVE-2019-11887CriMay 17, 2019
    risk 0.64cvss 9.8epss 0.02

    SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution.

  • CVE-2019-9951CriApr 24, 2019
    risk 0.64cvss 9.8epss 0.02

    Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page…

  • CVE-2019-11447HigApr 22, 2019
    risk 0.64cvss 8.8epss 0.52

    An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php.…