CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
25571 | CVE-2007-2214 | Candidate | Unrestricted file upload vulnerability in includes/upload_file.php in DmCMS allows remote attackers to upload arbitrary PHP scripts by placing a script"s contents in both the File2 and File3 parameters, and sending a ok.php?do=act Referer. | Assigned (20070424) | None (candidate not yet proposed) | View | |
59741 | CVE-2012-6498 | Candidate | Unrestricted file upload vulnerability in index.php in Atomymaxsite 2.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file, as exploited in the wild in October 2012. | Assigned (20130108) | None (candidate not yet proposed) | View | |
25083 | CVE-2007-1726 | Candidate | Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitrary files via the avatar function, which can later be accessed in uploads/. | Assigned (20070327) | None (candidate not yet proposed) | View | |
37807 | CVE-2009-0372 | Candidate | Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and an image content type via a users editProfile action, then accessing this file via a direct request to the file in images/avatar/uploaded/. | Assigned (20090130) | None (candidate not yet proposed) | View | |
27997 | CVE-2007-4640 | Candidate | Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files in uploads/ via an Uploads action. | Assigned (20070831) | None (candidate not yet proposed) | View |
Page 18746 of 20943, showing 5 records out of 104715 total, starting on record 93726, ending on 93730