CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
23238 | CVE-2006-7134 | Candidate | Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote attackers to upload and execute arbitrary files with executable extensions such as .php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20070305) | None (candidate not yet proposed) | View | |
23174 | CVE-2006-7070 | Candidate | Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload and execute arbitrary files via an nfile[] parameter with a filename that contains a .php extension followed by a valid image extension such as .gif or .jpg, then calling the rename function. | Assigned (20070227) | None (candidate not yet proposed) | View | |
42974 | CVE-2010-0390 | Candidate | Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max"s Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/. NOTE: some of these details are obtained from third party information. | Assigned (20100126) | None (candidate not yet proposed) | View | |
39705 | CVE-2009-2270 | Candidate | Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbitrary code by uploading a file with a double extension in the filename, then accessing this file via unspecified vectors, as demonstrated by a .jpg.php filename. | Assigned (20090701) | None (candidate not yet proposed) | View | |
36902 | CVE-2008-6785 | Candidate | Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as demonstrated by creating a name.php file. | Assigned (20090501) | None (candidate not yet proposed) | View |
Page 18752 of 20943, showing 5 records out of 104715 total, starting on record 93756, ending on 93760