CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
27539 | CVE-2007-4182 | Candidate | Unrestricted file upload vulnerability in index.php in WikiWebWeaver 1.1 and earlier allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .gif.php, which is accessible from data/documents/. | Assigned (20070807) | None (candidate not yet proposed) | View | |
43341 | CVE-2010-0757 | Candidate | Unrestricted file upload vulnerability in index.php/Attach in WikyBlog 1.7.3rc2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension using the uploadform action, then accessing it via a direct request to the file in userfiles/[username]/uploaded/. | Assigned (20100226) | None (candidate not yet proposed) | View | |
85181 | CVE-2015-7904 | Candidate | Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary JSP code via vectors involving an upload of an image file. | Assigned (20151022) | None (candidate not yet proposed) | View | |
31907 | CVE-2008-1790 | Candidate | Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a crafted logo file in the "Manage Settings" functionality. NOTE: remote exploitation is facilitated by a separate SQL injection vulnerability. | Assigned (20080415) | None (candidate not yet proposed) | View | |
26090 | CVE-2007-2733 | Candidate | Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts via unspecified vectors, which can be accessed in webfiles/. NOTE: this issue might be a duplicate of CVE-2004-1448. | Assigned (20070516) | None (candidate not yet proposed) | View |
Page 18748 of 20943, showing 5 records out of 104715 total, starting on record 93736, ending on 93740