CVE List

Id CVE No. Status Description Phase Votes Comments Actions
21120  CVE-2006-5016  Candidate  Unrestricted file upload vulnerability in admin/x_image.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to upload arbitrary files to the /imagebank directory.  Assigned (20060927)  None (candidate not yet proposed)    View
31612  CVE-2008-1495  Candidate  Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote authenticated administrators to upload and execute arbitrary PHP files via a modified content type in an ajout action, as demonstrated by (1) image/gif and (2) application/pdf.  Assigned (20080325)  None (candidate not yet proposed)    View
42228  CVE-2009-4793  Candidate  Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension via an addphotos action to adminpanel/index.php, and then accessing the file via a direct request with an images/gallery/ directory name. NOTE: some of these details are obtained from third party information.  Assigned (20100422)  None (candidate not yet proposed)    View
41541  CVE-2009-4106  Candidate  Unrestricted file upload vulnerability in admintools/editpage-2.php in Agoko CMS 0.4 and earlier allows remote attackers to inject and execute arbitrary PHP code via the filename and text parameters.  Assigned (20091128)  None (candidate not yet proposed)    View
41525  CVE-2009-4090  Candidate  Unrestricted file upload vulnerability in ajax/addComment.php in telepark.wiki 2.4.23 and earlier script allows remote attackers to execute arbitrary code by uploading a file with a name containing a NULL byte.  Assigned (20091127)  None (candidate not yet proposed)    View

Page 18728 of 20943, showing 5 records out of 104715 total, starting on record 93636, ending on 93640

Actions