CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
26786 | CVE-2007-3429 | Candidate | Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg. | Assigned (20070626) | None (candidate not yet proposed) | View | |
24592 | CVE-2007-1235 | Candidate | Unrestricted file upload vulnerability in sitex allows remote attackers to upload arbitrary PHP code via an avatar filename with a double extension such as .php.jpg, which fails verification and is saved as a .php file. | Assigned (20070303) | None (candidate not yet proposed) | View | |
32333 | CVE-2008-2216 | Candidate | Unrestricted file upload vulnerability in src/yopy_upload.php in Project-Based Calendaring System (PBCS) 0.7.1 allows remote authenticated users to upload arbitrary files to tmp/uploads. | Assigned (20080514) | None (candidate not yet proposed) | View | |
21026 | CVE-2006-4922 | Candidate | Unrestricted file upload vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to upload and execute arbitrary files with executable extensions. | Assigned (20060920) | None (candidate not yet proposed) | View | |
36848 | CVE-2008-6731 | Candidate | Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the renamed file in linkphoto/. | Assigned (20090420) | None (candidate not yet proposed) | View |
Page 18763 of 20943, showing 5 records out of 104715 total, starting on record 93811, ending on 93815