CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
37038 | CVE-2008-6921 | Candidate | Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photoes/. | Assigned (20090810) | None (candidate not yet proposed) | View | |
23727 | CVE-2007-0370 | Candidate | Unrestricted file upload vulnerability in index.php in phpBP RC3 (2.204) and earlier allows remote administrators to inject arbitrary PHP code into an upload/banners/ file via a banners add operation that uploads the PHP code through an image_form parameter specifying a multiple-extension filename such as .jpg.vil.gif.php, which is stored in upload/banners/ under a different name, and executable via a direct request. NOTE: a separate SQL injection issue could be leveraged to make this vulnerability reachable by remote unauthenticated attackers. | Assigned (20070119) | None (candidate not yet proposed) | View | |
36966 | CVE-2008-6849 | Candidate | Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a via a link that is listed by userfiles/number_shell.php. | Assigned (20090707) | None (candidate not yet proposed) | View | |
21949 | CVE-2006-5845 | Candidate | Unrestricted file upload vulnerability in index.php in Speedywiki 2.0 allows remote authenticated users to upload and execute arbitrary PHP code by setting the upload parameter to 1. | Assigned (20061109) | None (candidate not yet proposed) | View | |
36868 | CVE-2008-6751 | Candidate | Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in settings/my_photo. | Assigned (20090424) | None (candidate not yet proposed) | View |
Page 18747 of 20943, showing 5 records out of 104715 total, starting on record 93731, ending on 93735