CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41575  CVE-2009-4140  Candidate  Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Plugin before 1.4.3.2, and possibly other products, when register_globals is enabled, allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension through the name parameter with the code in the HTTP_RAW_POST_DATA parameter, then accessing it via a direct request to the file in tmp-upload-images/.  Assigned (20091201)  None (candidate not yet proposed)    View
69573  CVE-2014-2278  Candidate  Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension specified by the partitionIndex parameter and leveraging CVE-2014-2279.2 to access it via the directory specified by the fileId parameter.  Assigned (20140304)  None (candidate not yet proposed)    View
41188  CVE-2009-3753  Candidate  Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request to the file in userimages, related to register.php.  Assigned (20091022)  None (candidate not yet proposed)    View
27856  CVE-2007-4499  Candidate  Unrestricted file upload vulnerability in output.php in American Financing eMail Image Upload 4.1 allows remote attackers to upload and execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20070823)  None (candidate not yet proposed)    View
23217  CVE-2006-7113  Candidate  Unrestricted file upload vulnerability in P-News 2.0 allows remote attackers to upload and execute arbitrary files via an avatar file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20070305)  None (candidate not yet proposed)    View

Page 18755 of 20943, showing 5 records out of 104715 total, starting on record 93771, ending on 93775

Actions