CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26786  CVE-2007-3429  Candidate  Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.  Assigned (20070626)  None (candidate not yet proposed)    View
24592  CVE-2007-1235  Candidate  Unrestricted file upload vulnerability in sitex allows remote attackers to upload arbitrary PHP code via an avatar filename with a double extension such as .php.jpg, which fails verification and is saved as a .php file.  Assigned (20070303)  None (candidate not yet proposed)    View
32333  CVE-2008-2216  Candidate  Unrestricted file upload vulnerability in src/yopy_upload.php in Project-Based Calendaring System (PBCS) 0.7.1 allows remote authenticated users to upload arbitrary files to tmp/uploads.  Assigned (20080514)  None (candidate not yet proposed)    View
21026  CVE-2006-4922  Candidate  Unrestricted file upload vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to upload and execute arbitrary files with executable extensions.  Assigned (20060920)  None (candidate not yet proposed)    View
36848  CVE-2008-6731  Candidate  Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the renamed file in linkphoto/.  Assigned (20090420)  None (candidate not yet proposed)    View

Page 18763 of 20943, showing 5 records out of 104715 total, starting on record 93811, ending on 93815

Actions