CVE List

Id CVE No. Status Description Phase Votes Comments Actions
37205  CVE-2008-7088  Candidate  Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in a certain path. NOTE: this may be the same vulnerability as CVE-2008-0251, but this is not clear due to lack of details from the vendor.  Assigned (20090826)  None (candidate not yet proposed)    View
42253  CVE-2009-4818  Candidate  Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif.  Assigned (20100427)  None (candidate not yet proposed)    View
29093  CVE-2007-5736  Candidate  Unrestricted file upload vulnerability in upload.php in SeeBlick 1.0 Beta allows remote attackers to upload arbitrary files via unspecified vectors. NOTE: these files are stored with .html extensions, so the scope of the attack might be limited to resource consumption and possibly XSS.  Assigned (20071030)  None (candidate not yet proposed)    View
57715  CVE-2012-4472  Candidate  Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the directory specified by the filedir parameter.  Assigned (20120821)  None (candidate not yet proposed)    View
33479  CVE-2008-3362  Candidate  Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the upfile parameter, then accessing it via a direct request to the file in wp-content/plugins/downloads-manager/upload/.  Assigned (20080730)  None (candidate not yet proposed)    View

Page 18779 of 20943, showing 5 records out of 104715 total, starting on record 93891, ending on 93895

Actions