CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26760  CVE-2007-3403  Candidate  Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload and execute arbitrary PHP code in uploads/images/ via the uploadedFile[] parameter.  Assigned (20070626)  None (candidate not yet proposed)    View
38881  CVE-2009-1446  Candidate  Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some of these details are obtained from third party information.  Assigned (20090427)  None (candidate not yet proposed)    View
22674  CVE-2006-6570  Candidate  Unrestricted file upload vulnerability in upload.php in GenesisTrader 1.0 allows remote authenticated users to upload arbitrary files via unspecified vectors, possibly involving form.php and the ajoutfich "foap" action.  Assigned (20061214)  None (candidate not yet proposed)    View
37284  CVE-2008-7167  Candidate  Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.  Assigned (20090907)  None (candidate not yet proposed)    View
34545  CVE-2008-4428  Candidate  Unrestricted file upload vulnerability in upload.php in Phlatline"s Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in the top-level directory.  Assigned (20081003)  None (candidate not yet proposed)    View

Page 18778 of 20943, showing 5 records out of 104715 total, starting on record 93886, ending on 93890

Actions