CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
37049 | CVE-2008-6932 | Candidate | Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in send/files/. | Assigned (20090811) | None (candidate not yet proposed) | View | |
65300 | CVE-2013-5353 | Candidate | Unrestricted file upload vulnerability in system/controllers/ajax/attachments.php in Sharetronix 3.1.1.3, 3.1.1, and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory. | Assigned (20130821) | None (candidate not yet proposed) | View | |
22451 | CVE-2006-6347 | Candidate | Unrestricted file upload vulnerability in TFT-Gallery allows remote authenticated administrators to upload arbitrary .php files, possibly using admin/index.php. NOTE: this can be leveraged with CVE-2006-1412 to create a remote unauthenticated vector. | Assigned (20061206) | None (candidate not yet proposed) | View | |
34995 | CVE-2008-4878 | Candidate | Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the uploaded file. | Assigned (20081031) | None (candidate not yet proposed) | View | |
96006 | CVE-2016-9186 | Candidate | Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | Assigned (20161104) | None (candidate not yet proposed) | View |
Page 18764 of 20943, showing 5 records out of 104715 total, starting on record 93816, ending on 93820