CVE List

Id CVE No. Status Description Phase Votes Comments Actions
29884  CVE-2007-6527  Candidate  uploadimg.php in the Automatic Image Upload with Thumbnails (imgUpload) module 1.3.2 for PunBB only verifies the Content-type field of uploaded files, which allows remote attackers to upload and execute arbitrary content via a file with a (1) JPG, (2) GIF, or (3) PNG MIME type.  Assigned (20071227)  None (candidate not yet proposed)    View
9973  CVE-2004-1545  Candidate  UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.  Assigned (20050220)  None (candidate not yet proposed)    View
36730  CVE-2008-6613  Candidate  uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request.  Assigned (20090406)  None (candidate not yet proposed)    View
13087  CVE-2005-1881  Candidate  upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.  Assigned (20050608)  None (candidate not yet proposed)    View
8313  CVE-2003-1489  Candidate  upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.  Assigned (20071024)  None (candidate not yet proposed)    View

Page 812 of 20943, showing 5 records out of 104715 total, starting on record 4056, ending on 4060

Actions