CVE List

Id CVE No. Status Description Phase Votes Comments Actions
20706  CVE-2006-4602  Candidate  Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory.  Assigned (20060906)  None (candidate not yet proposed)    View
31347  CVE-2008-1230  Candidate  Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbitrary .jsp files via an unspecified manipulation that attaches a .jsp file to an "entry page."  Assigned (20080310)  None (candidate not yet proposed)    View
35794  CVE-2008-5677  Candidate  Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root, allows remote authenticated users with upload capability to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under items/, related to the ReplaceBadFilenameChars function in include/ItemAdder.php. NOTE: some of these details are obtained from third party information.  Assigned (20081218)  None (candidate not yet proposed)    View
26099  CVE-2007-2742  Candidate  Unrestricted file upload vulnerability in labs.beffa.org w2box 4.0.0 Beta4 allows remote attackers to upload arbitrary PHP code via a filename with a double extension such as .php.jpg.  Assigned (20070517)  None (candidate not yet proposed)    View
65908  CVE-2013-5961  Candidate  Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.  Assigned (20130930)  None (candidate not yet proposed)    View

Page 18749 of 20943, showing 5 records out of 104715 total, starting on record 93741, ending on 93745

Actions