CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
62061 | CVE-2013-2114 | Candidate | Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. | Assigned (20130219) | None (candidate not yet proposed) | View | |
39581 | CVE-2009-2146 | Candidate | Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name. | Assigned (20090622) | None (candidate not yet proposed) | View | |
77965 | CVE-2015-0702 | Candidate | Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated users to execute arbitrary code by using the languageShortName parameter to upload a file that provides shell access, aka Bug ID CSCus95712. | Assigned (20150107) | None (candidate not yet proposed) | View | |
75386 | CVE-2014-8085 | Candidate | Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass before 3.4.3 allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in an unspecified directory. | Assigned (20141009) | None (candidate not yet proposed) | View | |
89733 | CVE-2016-2914 | Candidate | Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to execute arbitrary code by specifying an unexpected file extension. | Assigned (20160309) | None (candidate not yet proposed) | View |
Page 18767 of 20943, showing 5 records out of 104715 total, starting on record 93831, ending on 93835