CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
30490 | CVE-2008-0373 | Candidate | Unrestricted file upload vulnerability in PHP F1 Max"s File Uploader allows remote attackers to upload and execute arbitrary PHP files. | Assigned (20080122) | None (candidate not yet proposed) | View | |
56819 | CVE-2012-3576 | Candidate | Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/wpstorecart. | Assigned (20120615) | None (candidate not yet proposed) | View | |
15627 | CVE-2005-4423 | Candidate | Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to an accessible directory, as demonstrated using a file with a .php extension, aka "upload phpshell." | Assigned (20051220) | None (candidate not yet proposed) | View | |
24996 | CVE-2007-1639 | Candidate | Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable extension, which is then accessed by the (1) calendar or (2) file management module, or possibly unspecified other files. | Assigned (20070323) | None (candidate not yet proposed) | View | |
37046 | CVE-2008-6929 | Candidate | Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in cars/cars_images/. | Assigned (20090811) | None (candidate not yet proposed) | View |
Page 18757 of 20943, showing 5 records out of 104715 total, starting on record 93781, ending on 93785