VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 65 of 216
  • CVE-2020-28687HigNov 17, 2020
    risk 0.61cvss 8.8epss 0.12

    The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.

  • CVE-2020-12255HigMay 18, 2020
    risk 0.61cvss 8.8epss 0.53

    rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php accepts a file upload by checking content-type without considering the file extension and header. Thus, an attacker can exploit this by uploading a…

  • CVE-2012-6649CriJan 23, 2020
    risk 0.61cvss 9.8epss 0.16

    WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.

  • CVE-2014-1214HigNov 13, 2019
    risk 0.61cvss 8.8epss 0.04

    views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute arbitrary files via a crafted (1) dest parameter and (2) arbitrary extension in the Filename parameter.

  • CVE-2019-9189HigJun 5, 2019
    risk 0.61cvss 8.8epss 0.12

    Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately executed because of root code execution, not as a web server user, allowing an…

  • CVE-2019-11446HigApr 22, 2019
    risk 0.61cvss 8.8epss 0.08

    An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files section in the File Manager field contains an arbitrary file upload vulnerability via upload.php. The $IllegalExtensions value only…

  • CVE-2019-9581HigMar 6, 2019
    risk 0.61cvss 8.8epss 0.13

    phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresenter.php does not ensure an image file extension.

  • CVE-2018-20166HigJan 2, 2019
    risk 0.61cvss 8.8epss 0.07

    A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishandles extension checking. It accepts uploads of PHP content if the first few characters match GIF data, and the filename ends in…

  • CVE-2018-19550HigNov 26, 2018
    risk 0.61cvss 8.8epss 0.06

    Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a admin/temp/surveys/ URI.

  • CVE-2018-17442HigOct 8, 2018
    risk 0.61cvss 8.8epss 0.14

    An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endpoint allows remote authenticated users to execute arbitrary PHP code.

  • CVE-2018-12519HigJun 19, 2018
    risk 0.61cvss 8.8epss 0.08

    An issue was discovered in ShopNx through 2017-11-17. The vulnerability allows a remote attacker to upload any malicious file to a Node.js application. An attacker can upload a malicious HTML file that contains a JavaScript payload to steal a user's credentials.

  • CVE-2018-10577HigMay 2, 2018
    risk 0.61cvss 8.8epss 0.07

    An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root,…

  • CVE-2017-14521HigJan 26, 2018
    risk 0.61cvss 8.8epss 0.07

    In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.

  • CVE-2017-17874HigDec 27, 2017
    risk 0.61cvss 8.8epss 0.06

    Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.

  • CVE-2017-15957HigOct 29, 2017
    risk 0.61cvss 8.8epss 0.04

    my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.

  • CVE-2011-4334HigOct 23, 2017
    risk 0.61cvss 8.8epss 0.06

    edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP files via a PHP file with a .gif extension in the userfile parameter.

  • CVE-2017-14704HigSep 26, 2017
    risk 0.61cvss 8.8epss 0.08

    Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct…

  • CVE-2017-12929HigSep 21, 2017
    risk 0.61cvss 8.8epss 0.10

    Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Execution.

  • CVE-2017-9380HigJun 2, 2017
    risk 0.61cvss 8.8epss 0.15

    OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application.

  • CVE-2015-3884HigMar 17, 2017
    risk 0.61cvss 8.8epss 0.14

    Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pages in qdPM 8.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing…