VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 61 of 222
  • CVE-2019-9825CriMar 14, 2019
    risk 0.64cvss 9.8epss 0.02

    FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Index to modify the set of allowable file extensions, as demonstrated by adding php to the default jpg,gif,png,jpeg setting, and then using the "add article"…

  • CVE-2019-0259CriFeb 15, 2019
    risk 0.64cvss 9.8epss 0.02

    SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation.

  • CVE-2019-7684CriFeb 9, 2019
    risk 0.64cvss 9.8epss 0.02

    inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.common.controller.VideoUploadController#gok4 (com/inxedu/os/common/controller/VideoUploadController.java). The attacker uses the…

  • CVE-2019-6139CriFeb 7, 2019
    risk 0.64cvss 9.8epss 0.02

    Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. Successful exploitation of this vulnerability may lead to remote code execution. To fix this vulnerability, upgrade to FUID version 1.3 or higher. To prevent…

  • CVE-2018-5204CriDec 28, 2018
    risk 0.64cvss 9.8epss 0.02

    ML Report version Between 2.00.000.0000 and 2.18.628.5980 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. this can be leveraged for code execution.

  • CVE-2018-1000811HigDec 20, 2018
    risk 0.64cvss 8.8epss 0.48

    bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This attack appear to be exploitable via malicious user have to upload a crafted payload containing PHP…

  • CVE-2018-19692CriNov 29, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploading a .php file with the image/jpeg content type.

  • CVE-2018-9209CriNov 19, 2018
    risk 0.64cvss 9.8epss 0.02

    Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2

  • CVE-2018-9207CriNov 19, 2018
    risk 0.64cvss 9.8epss 0.03

    Arbitrary file upload in jQuery Upload File <= 4.0.2

  • CVE-2018-19355CriNov 19, 2018
    risk 0.64cvss 9.8epss 0.04

    modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations…

  • CVE-2018-9208CriNov 5, 2018
    risk 0.64cvss 9.8epss 0.03

    Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta

  • CVE-2018-18934CriNov 5, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a ZIP file containing arbitrary PHP code (that is extracted and can be executed). This can also be…

  • CVE-2018-18888CriNov 1, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files because the file extension is not properly checked and uploaded files are not properly renamed.

  • CVE-2018-18874CriOct 31, 2018
    risk 0.64cvss 9.8epss 0.02

    nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Content-Type: application/octet-stream" to the index.php?action=file_manager_upload URI.

  • CVE-2018-18830CriOct 30, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of JSP code with a .png filename,…

  • CVE-2018-18752CriOct 29, 2018
    risk 0.64cvss 9.8epss 0.02

    Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo parameter.

  • CVE-2015-9271CriOct 4, 2018
    risk 0.64cvss 9.8epss 0.04

    The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code,…

  • CVE-2018-17573CriSep 28, 2018
    risk 0.64cvss 9.8epss 0.03

    The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configuration of FCKeditor under fckeditor/editor/filemanager/browser/default/browser.html, fckeditor/editor/filemanager/connectors/test.html, and…

  • CVE-2018-16731CriSep 8, 2018
    risk 0.64cvss 9.8epss 0.01

    CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.

  • CVE-2018-0645CriSep 7, 2018
    risk 0.64cvss 9.8epss 0.02

    MTAppjQuery 1.8.1 and earlier allows remote PHP code execution via unspecified vectors.