CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40503  CVE-2009-3068  Candidate  Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a direct request to the file in the robohelp/robo/reserved/web directory under its sessionid subdirectory, as demonstrated by the vd_adobe module in VulnDisco Pack Professional 8.7 through 8.11.  Assigned (20090904)  None (candidate not yet proposed)    View
66767  CVE-2013-6820  Candidate  Unrestricted file upload vulnerability in the SAP NetWeaver Development Infrastructure (NWDI) allows remote attackers to execute arbitrary code by uploading a file with an executable extension via unspecified vectors.  Assigned (20131119)  None (candidate not yet proposed)    View
88532  CVE-2016-1713  Candidate  Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in test/logo/. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6000.  Assigned (20160112)  None (candidate not yet proposed)    View
72758  CVE-2014-5460  Candidate  Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.  Assigned (20140826)  None (candidate not yet proposed)    View
25382  CVE-2007-2025  Candidate  Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.  Assigned (20070413)  None (candidate not yet proposed)    View

Page 18774 of 20943, showing 5 records out of 104715 total, starting on record 93866, ending on 93870

Actions