CVE List

Id CVE No. Status Description Phase Votes Comments Actions
35812  CVE-2008-5695  Candidate  wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script"s pathname to active_plugins.  Assigned (20081219)  None (candidate not yet proposed)    View
101348  CVE-2017-4528  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161226)  None (candidate not yet proposed)    View
36068  CVE-2008-5951  Candidate  ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for workDB/templatemonster.mdb.  Assigned (20090123)  None (candidate not yet proposed)    View
101604  CVE-2017-4784  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161226)  None (candidate not yet proposed)    View
36324  CVE-2008-6207  Candidate  Unrestricted file upload vulnerability in form_upload.php in PHPG Upload 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20090219)  None (candidate not yet proposed)    View

Page 18799 of 20943, showing 5 records out of 104715 total, starting on record 93991, ending on 93995

Actions