NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 62014 | CVE-2006-3336 | TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extensions that are not .txt. NOTE: this is only a vulnerability when the server allows script execution in the pub directory. | 2 | 4 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 62526 | CVE-2006-3859 | IBM Informix Dynamic Server (IDS) allows remote authenticated users to create and overwrite arbitrary files via the (1) LOTOFILE and (2) trl_tracefile_set functions, and the (3) "SET DEBUG FILE" commands. | 2 | 4 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 7487 | CVE-2011-0418 | The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command. | 2 | 4 | Medium | 2017-01-07 | 2011-09-21 | View | |
| 11327 | CVE-2011-5067 | move_uploaded_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation path in an error message. | 2 | 4 | Medium | 2017-01-07 | 2012-10-12 | View | |
| 31551 | CVE-2014-3349 | Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not validate file types during the handling of file submission, which allows remote authenticated users to upload arbitrary files via a crafted request, aka Bug ID CSCuh87410. | 2 | 4 | Medium | 2017-01-19 | 2017-01-06 | View |
Page 14460 of 17672, showing 5 records out of 88360 total, starting on record 72296, ending on 72300