CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
54396 | CVE-2012-1153 | Candidate | Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory. | Assigned (20120214) | None (candidate not yet proposed) | View | |
36734 | CVE-2008-6617 | Candidate | Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/. | Assigned (20090406) | None (candidate not yet proposed) | View | |
24612 | CVE-2007-1255 | Candidate | Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticated administrators to execute arbitrary PHP code by uploading a crafted GIF smiley image with a .php extension via the uploadimage parameter to admin.php, which can be later accessed via a direct request for the file in smileys/. NOTE: this can be leveraged with a separate SQL injection issue for remote unauthenticated attacks. | Assigned (20070303) | None (candidate not yet proposed) | View | |
41151 | CVE-2009-3716 | Candidate | Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in smilies/. | Assigned (20091016) | None (candidate not yet proposed) | View | |
57279 | CVE-2012-4036 | Candidate | Unrestricted file upload vulnerability in admin.php in PBBoard 2.1.4 allows remote administrators to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the addons directory. NOTE: this vulnerability can be leveraged by remote attackers using CVE-2012-1216. | Assigned (20120720) | None (candidate not yet proposed) | View |
Page 18722 of 20943, showing 5 records out of 104715 total, starting on record 93606, ending on 93610