VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 59 of 222
  • CVE-2019-15936CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.02

    Intesync Solismed 3.3sp allows Insecure File Upload.

  • CVE-2019-19595CriDec 5, 2019
    risk 0.64cvss 9.8epss 0.04

    reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.

  • CVE-2019-19594CriDec 5, 2019
    risk 0.64cvss 9.8epss 0.04

    reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.

  • CVE-2019-12271CriNov 18, 2019
    risk 0.64cvss 9.8epss 0.02

    Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the server side.

  • CVE-2019-12719CriNov 12, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an incorrect access control vulnerability that can allow an unauthenticated user to upload files via a modified authority parameter.

  • CVE-2011-1134CriNov 5, 2019
    risk 0.64cvss 9.8epss 0.03

    Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.

  • CVE-2019-14451CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.04

    RepetierServer.exe in Repetier-Server 0.8 through 0.91 does not properly validate the XML data structure provided when uploading a new printer configuration. When this is combined with CVE-2019-14450, an attacker can upload an "external command" configuration as a printer…

  • CVE-2019-16700CriOct 16, 2019
    risk 0.64cvss 9.8epss 0.03

    The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below, this results in Remote Code Execution. In versions later than 1.2.2, this can result in Denial of Service, since…

  • CVE-2015-9479CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.03

    The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.

  • CVE-2015-9471CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.04

    The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.

  • CVE-2019-15751CriOct 7, 2019
    risk 0.64cvss 9.8epss 0.04

    An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM file with an executable extension. This allows an unauthenticated attacker to upload a malicious file (containing PHP code to execute…

  • CVE-2019-15748CriOct 7, 2019
    risk 0.64cvss 9.8epss 0.02

    SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages. An unauthenticated attacker could use the upload and import functionality to import a malicious SCORM package that includes a PHP file, which could…

  • CVE-2016-10995CriSep 18, 2019
    risk 0.64cvss 9.8epss 0.02

    The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php.

  • CVE-2019-15131CriSep 17, 2019
    risk 0.64cvss 9.8epss 0.02

    In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to be uploaded to Code42 servers and executed. This vulnerability could allow an attacker to create directories and save files on Code42…

  • CVE-2016-10955CriSep 13, 2019
    risk 0.64cvss 9.8epss 0.02

    The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.

  • CVE-2016-10954CriSep 13, 2019
    risk 0.64cvss 9.8epss 0.02

    The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.

  • CVE-2019-16192CriSep 9, 2019
    risk 0.64cvss 9.8epss 0.02

    upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbitrary PHP code through module management files, as demonstrated by a .php file in a ZIP archive.

  • CVE-2019-13187CriSep 5, 2019
    risk 0.64cvss 9.8epss 0.02

    The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php.

  • CVE-2019-13976CriSep 4, 2019
    risk 0.64cvss 9.8epss 0.02

    eGain Chat 15.0.3 allows unrestricted file upload.

  • CVE-2019-15524CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.03

    CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote code execution by visiting a photo/upload/2019/ URI.