CVE List

Id CVE No. Status Description Phase Votes Comments Actions
32075  CVE-2008-1958  Candidate  Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with a .php extension.  Assigned (20080425)  None (candidate not yet proposed)    View
64412  CVE-2013-4465  Candidate  Unrestricted file upload vulnerability in the avatar upload functionality in Simple Machines Forum before 2.0.6 and 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.  Assigned (20130612)  None (candidate not yet proposed)    View
79364  CVE-2015-2087  Candidate  Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.  Assigned (20150226)  None (candidate not yet proposed)    View
96088  CVE-2016-9268  Candidate  Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.  Assigned (20161110)  None (candidate not yet proposed)    View
33859  CVE-2008-3742  Candidate  Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, which is not validated.  Assigned (20080820)  None (candidate not yet proposed)    View

Page 18766 of 20943, showing 5 records out of 104715 total, starting on record 93826, ending on 93830

Actions