CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25381  CVE-2007-2024  Candidate  Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.x allows remote attackers to upload arbitrary PHP files with a (1) php3, (2) php4, or (3) php5 extension.  Assigned (20070413)  None (candidate not yet proposed)    View
87150  CVE-2016-0854  Candidate  Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.  Assigned (20151217)  None (candidate not yet proposed)    View
64845  CVE-2013-4898  Candidate  Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in public/temporary/timeline/.  Assigned (20130724)  None (candidate not yet proposed)    View
41325  CVE-2009-3890  Candidate  Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.  Assigned (20091105)  None (candidate not yet proposed)    View
33356  CVE-2008-3239  Candidate  Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is enabled, allows remote attackers to upload and execute arbitrary code via a filename in the CONF[CRON_LOGFILE] parameter and file contents in the CONF[LOCALE_LONG_DATE_TIME] parameter.  Assigned (20080721)  None (candidate not yet proposed)    View

Page 18775 of 20943, showing 5 records out of 104715 total, starting on record 93871, ending on 93875

Actions