CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
26760 | CVE-2007-3403 | Candidate | Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload and execute arbitrary PHP code in uploads/images/ via the uploadedFile[] parameter. | Assigned (20070626) | None (candidate not yet proposed) | View | |
38881 | CVE-2009-1446 | Candidate | Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some of these details are obtained from third party information. | Assigned (20090427) | None (candidate not yet proposed) | View | |
22674 | CVE-2006-6570 | Candidate | Unrestricted file upload vulnerability in upload.php in GenesisTrader 1.0 allows remote authenticated users to upload arbitrary files via unspecified vectors, possibly involving form.php and the ajoutfich "foap" action. | Assigned (20061214) | None (candidate not yet proposed) | View | |
37284 | CVE-2008-7167 | Candidate | Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory. | Assigned (20090907) | None (candidate not yet proposed) | View | |
34545 | CVE-2008-4428 | Candidate | Unrestricted file upload vulnerability in upload.php in Phlatline"s Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in the top-level directory. | Assigned (20081003) | None (candidate not yet proposed) | View |
Page 18778 of 20943, showing 5 records out of 104715 total, starting on record 93886, ending on 93890