CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46897  CVE-2010-4313  Candidate  Unrestricted file upload vulnerability in fileman_file_upload.php in Orbis CMS 1.0.2 allows remote authenticated users to execute arbitrary code by uploading a .php file, and then accessing it via a direct request to the file in uploads/.  Assigned (20101129)  None (candidate not yet proposed)    View
37143  CVE-2008-7026  Candidate  Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/.  Assigned (20090821)  None (candidate not yet proposed)    View
20721  CVE-2006-4617  Candidate  Unrestricted file upload vulnerability in fileupload.html in vtiger CRM 4.2.4, and possibly earlier versions, allows remote attackers to upload and execute arbitrary files with executable extensions in the /cashe/mails folder.  Assigned (20060906)  None (candidate not yet proposed)    View
78864  CVE-2015-1587  Candidate  Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a request to a predictable filename in tmp/.  Assigned (20150211)  None (candidate not yet proposed)    View
30007  CVE-2007-6650  Candidate  Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using the image/gif content type, and possibly other image and PDF content types, as demonstrated by uploading a .htaccess file.  Assigned (20080103)  None (candidate not yet proposed)    View

Page 18739 of 20943, showing 5 records out of 104715 total, starting on record 93691, ending on 93695

Actions