CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
15626 | CVE-2005-4422 | Candidate | Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums. | Assigned (20051220) | None (candidate not yet proposed) | View | |
44098 | CVE-2010-1514 | Candidate | Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory. | Assigned (20100426) | None (candidate not yet proposed) | View | |
23480 | CVE-2007-0123 | Candidate | Unrestricted file upload vulnerability in Uber Uploader 4.2 allows remote attackers to upload and execute arbitrary PHP scripts by naming them with a .phtml extension, which bypasses the .php extension check but is still executable on some server configurations. | Assigned (20070108) | None (candidate not yet proposed) | View | |
72725 | CVE-2014-5428 | Candidate | Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to execute arbitrary code by uploading a shell script. | Assigned (20140822) | None (candidate not yet proposed) | View | |
33234 | CVE-2008-3117 | Candidate | Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a .php file with a content type of (1) image/gif, (2) image/jpeg, or (3) image/pjpeg, then accessing it via a direct request to the file under pictures/. | Assigned (20080710) | None (candidate not yet proposed) | View |
Page 18776 of 20943, showing 5 records out of 104715 total, starting on record 93876, ending on 93880