CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,314)
page 59 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-11344 | Cri | 0.64 | 9.8 | 0.04 | Apr 19, 2019 | data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked. | ||
| CVE-2019-11223 | Cri | 0.64 | 9.8 | 0.09 | Apr 18, 2019 | An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension. | ||
| CVE-2019-3940 | Cri | 0.64 | 9.8 | 0.04 | Apr 9, 2019 | Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code. | ||
| CVE-2019-10647 | Cri | 0.64 | 9.8 | 0.07 | Mar 30, 2019 | ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of a lack of inc/zzz_file.php restrictions. For example, source%5B%5D=http%3A%2F%2F192.168.0.1%2Ftest.p… | ||
| CVE-2019-10276 | Cri | 0.64 | 9.8 | 0.02 | Mar 29, 2019 | Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the image/jpeg content type. | ||
| CVE-2018-19514 | Cri | 0.64 | 9.8 | 0.05 | Mar 21, 2019 | In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. Exploitation requires authentication bypass to access administrative functions of the site to upload a crafted CSV file with a malicious payload that becomes… | ||
| CVE-2019-9825 | Cri | 0.64 | 9.8 | 0.02 | Mar 14, 2019 | FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Index to modify the set of allowable file extensions, as demonstrated by adding php to the default jpg,gif,png,jpeg setting, and then using the "add article"… | ||
| CVE-2019-0259 | Cri | 0.64 | 9.8 | 0.02 | Feb 15, 2019 | SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation. | ||
| CVE-2019-7684 | Cri | 0.64 | 9.8 | 0.02 | Feb 9, 2019 | inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.common.controller.VideoUploadController#gok4 (com/inxedu/os/common/controller/VideoUploadController.java). The attacker uses the… | ||
| CVE-2019-6139 | Cri | 0.64 | 9.8 | 0.02 | Feb 7, 2019 | Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. Successful exploitation of this vulnerability may lead to remote code execution. To fix this vulnerability, upgrade to FUID version 1.3 or higher. To prevent… | ||
| CVE-2018-5204 | Cri | 0.64 | 9.8 | 0.02 | Dec 28, 2018 | ML Report version Between 2.00.000.0000 and 2.18.628.5980 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. this can be leveraged for code execution. | ||
| CVE-2018-1000811 | Hig | 0.64 | 8.8 | 0.48 | Dec 20, 2018 | bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This attack appear to be exploitable via malicious user have to upload a crafted payload containing PHP… | ||
| CVE-2018-19692 | Cri | 0.64 | 9.8 | 0.02 | Nov 29, 2018 | An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploading a .php file with the image/jpeg content type. | ||
| CVE-2018-9209 | Cri | 0.64 | 9.8 | 0.02 | Nov 19, 2018 | Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2 | ||
| CVE-2018-9207 | Cri | 0.64 | 9.8 | 0.03 | Nov 19, 2018 | Arbitrary file upload in jQuery Upload File <= 4.0.2 | ||
| CVE-2018-19355 | Cri | 0.64 | 9.8 | 0.04 | Nov 19, 2018 | modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations… | ||
| CVE-2018-9208 | Cri | 0.64 | 9.8 | 0.03 | Nov 5, 2018 | Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta | ||
| CVE-2018-18934 | Cri | 0.64 | 9.8 | 0.01 | Nov 5, 2018 | An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a ZIP file containing arbitrary PHP code (that is extracted and can be executed). This can also be… | ||
| CVE-2018-18888 | Cri | 0.64 | 9.8 | 0.01 | Nov 1, 2018 | An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files because the file extension is not properly checked and uploaded files are not properly renamed. | ||
| CVE-2018-18874 | Cri | 0.64 | 9.8 | 0.02 | Oct 31, 2018 | nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Content-Type: application/octet-stream" to the index.php?action=file_manager_upload URI. |
- risk 0.64cvss 9.8epss 0.04
data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked.
- risk 0.64cvss 9.8epss 0.09
An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
- risk 0.64cvss 9.8epss 0.04
Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.07
ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of a lack of inc/zzz_file.php restrictions. For example, source%5B%5D=http%3A%2F%2F192.168.0.1%2Ftest.p…
- risk 0.64cvss 9.8epss 0.02
Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the image/jpeg content type.
- risk 0.64cvss 9.8epss 0.05
In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. Exploitation requires authentication bypass to access administrative functions of the site to upload a crafted CSV file with a malicious payload that becomes…
- risk 0.64cvss 9.8epss 0.02
FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Index to modify the set of allowable file extensions, as demonstrated by adding php to the default jpg,gif,png,jpeg setting, and then using the "add article"…
- risk 0.64cvss 9.8epss 0.02
SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation.
- risk 0.64cvss 9.8epss 0.02
inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.common.controller.VideoUploadController#gok4 (com/inxedu/os/common/controller/VideoUploadController.java). The attacker uses the…
- risk 0.64cvss 9.8epss 0.02
Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. Successful exploitation of this vulnerability may lead to remote code execution. To fix this vulnerability, upgrade to FUID version 1.3 or higher. To prevent…
- risk 0.64cvss 9.8epss 0.02
ML Report version Between 2.00.000.0000 and 2.18.628.5980 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. this can be leveraged for code execution.
- risk 0.64cvss 8.8epss 0.48
bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This attack appear to be exploitable via malicious user have to upload a crafted payload containing PHP…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploading a .php file with the image/jpeg content type.
- risk 0.64cvss 9.8epss 0.02
Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2
- risk 0.64cvss 9.8epss 0.03
Arbitrary file upload in jQuery Upload File <= 4.0.2
- risk 0.64cvss 9.8epss 0.04
modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations…
- risk 0.64cvss 9.8epss 0.03
Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a ZIP file containing arbitrary PHP code (that is extracted and can be executed). This can also be…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files because the file extension is not properly checked and uploaded files are not properly renamed.
- risk 0.64cvss 9.8epss 0.02
nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Content-Type: application/octet-stream" to the index.php?action=file_manager_upload URI.