VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 60 of 222
  • CVE-2019-11031CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, and then execute these files with SYSTEM privileges.

  • CVE-2019-15091CriAug 16, 2019
    risk 0.64cvss 9.8epss 0.02

    filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.

  • CVE-2019-13973CriJul 19, 2019
    risk 0.64cvss 9.8epss 0.02

    LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used.

  • CVE-2019-12803CriJul 10, 2019
    risk 0.64cvss 9.8epss 0.02

    In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell upload, an attacker can use the webshell to perform remote code exection such as…

  • CVE-2019-12971CriJul 5, 2019
    risk 0.64cvss 9.8epss 0.02

    BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type.

  • CVE-2019-13082CriJun 30, 2019
    risk 0.64cvss 9.8epss 0.04

    Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This means that by putting a .php…

  • CVE-2019-9642CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourth line of a .php file, as demonstrated by a PoC.php created by the guest account, with execution…

  • CVE-2019-11185CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.04

    The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted executable file extension in conjunction with…

  • CVE-2019-12377CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.06

    A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution.

  • CVE-2016-10752CriMay 24, 2019
    risk 0.64cvss 9.8epss 0.02

    serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename.

  • CVE-2019-12150CriMay 24, 2019
    risk 0.64cvss 9.8epss 0.02

    Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under the UltimateEditorInclude/UserFiles/ URI.

  • CVE-2019-11887CriMay 17, 2019
    risk 0.64cvss 9.8epss 0.02

    SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution.

  • CVE-2019-9951CriApr 24, 2019
    risk 0.64cvss 9.8epss 0.02

    Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page…

  • CVE-2019-11447HigApr 22, 2019
    risk 0.64cvss 8.8epss 0.52

    An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php.…

  • CVE-2019-11344CriApr 19, 2019
    risk 0.64cvss 9.8epss 0.04

    data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked.

  • CVE-2019-11223CriApr 18, 2019
    risk 0.64cvss 9.8epss 0.09

    An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.

  • CVE-2019-3940CriApr 9, 2019
    risk 0.64cvss 9.8epss 0.04

    Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote attacker can use this vulnerability to execute arbitrary code.

  • CVE-2019-10647CriMar 30, 2019
    risk 0.64cvss 9.8epss 0.07

    ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of a lack of inc/zzz_file.php restrictions. For example, source%5B%5D=http%3A%2F%2F192.168.0.1%2Ftest.p…

  • CVE-2019-10276CriMar 29, 2019
    risk 0.64cvss 9.8epss 0.02

    Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the image/jpeg content type.

  • CVE-2018-19514CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.05

    In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. Exploitation requires authentication bypass to access administrative functions of the site to upload a crafted CSV file with a malicious payload that becomes…