CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23238  CVE-2006-7134  Candidate  Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote attackers to upload and execute arbitrary files with executable extensions such as .php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20070305)  None (candidate not yet proposed)    View
23174  CVE-2006-7070  Candidate  Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload and execute arbitrary files via an nfile[] parameter with a filename that contains a .php extension followed by a valid image extension such as .gif or .jpg, then calling the rename function.  Assigned (20070227)  None (candidate not yet proposed)    View
42974  CVE-2010-0390  Candidate  Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max"s Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/. NOTE: some of these details are obtained from third party information.  Assigned (20100126)  None (candidate not yet proposed)    View
39705  CVE-2009-2270  Candidate  Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbitrary code by uploading a file with a double extension in the filename, then accessing this file via unspecified vectors, as demonstrated by a .jpg.php filename.  Assigned (20090701)  None (candidate not yet proposed)    View
36902  CVE-2008-6785  Candidate  Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as demonstrated by creating a name.php file.  Assigned (20090501)  None (candidate not yet proposed)    View

Page 18752 of 20943, showing 5 records out of 104715 total, starting on record 93756, ending on 93760

Actions