CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3255  CVE-2001-0437  Candidate  upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.  Interim (20010911)  ACCEPT(3) Baker, Cole, Ziese | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:dcforum-az-file-upload(6393)  View
9078  CVE-2004-0650  Candidate  UploadServlet in Cisco Collaboration Server (CCS) running ServletExec before 3.0E allows remote attackers to upload and execute arbitrary files via a direct call to the UploadServlet URL.  Assigned (20040709)  None (candidate not yet proposed)    View
3129  CVE-2001-0308  Candidate  UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.  Modified (20080213)  MODIFY(1) Frech | NOOP(4) Bishop, Cole, Wall, Ziese  Frech> XF:bajie-directory-traversal(6115)  View
22481  CVE-2006-6377  Candidate  Uploadscript 1.2 and earlier stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain the admin password hash via a direct request for /password.txt.  Assigned (20061207)  None (candidate not yet proposed)    View
27289  CVE-2007-3932  Candidate  uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows remote attackers to upload and execute arbitrary PHP code in the img/ folder.  Assigned (20070720)  None (candidate not yet proposed)    View

Page 811 of 20943, showing 5 records out of 104715 total, starting on record 4051, ending on 4055

Actions