CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
46548 | CVE-2010-3964 | Candidate | Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability." | Assigned (20101014) | None (candidate not yet proposed) | View | |
96007 | CVE-2016-9187 | Candidate | Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | Assigned (20161104) | None (candidate not yet proposed) | View | |
34884 | CVE-2008-4767 | Candidate | Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploading a file with (1) .htm, (2) .html, or (3) .txt extensions, then accessing it via a direct request to the file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: it is unclear how allowing the upload of .html or .txt files supports arbitrary code execution; this might be legitimate functionality. | Assigned (20081027) | None (candidate not yet proposed) | View | |
48590 | CVE-2011-0678 | Candidate | Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code by uploading an executable file via the UploadDirectory and Accepted Extensions fields in the getImagefile component of EasyEdit.cfm. | Assigned (20110128) | None (candidate not yet proposed) | View | |
37118 | CVE-2008-7001 | Candidate | Unrestricted file upload vulnerability in the file manager in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary code via unknown vectors. | Assigned (20090817) | None (candidate not yet proposed) | View |
Page 18768 of 20943, showing 5 records out of 104715 total, starting on record 93836, ending on 93840