NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
56313  CVE-2007-4182  Unrestricted file upload vulnerability in index.php in WikiWebWeaver 1.1 and earlier allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .gif.php, which is accessible from data/documents/.    7.5  High  2017-01-07  2008-09-05  View
12299  CVE-2010-0757  Unrestricted file upload vulnerability in index.php/Attach in WikyBlog 1.7.3rc2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension using the uploadform action, then accessing it via a direct request to the file in userfiles/[username]/uploaded/.    6.5  Medium  2017-01-18  2010-06-05  View
28302  CVE-2015-7904  Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary JSP code via vectors involving an upload of an image file.    6.5  Medium  2017-01-19  2015-10-28  View
1730  CVE-2008-1790  Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a crafted logo file in the "Manage Settings" functionality. NOTE: remote exploitation is facilitated by a separate SQL injection vulnerability.    6.5  Medium  2017-01-03  2011-03-07  View
54897  CVE-2007-2733  Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts via unspecified vectors, which can be accessed in webfiles/. NOTE: this issue might be a duplicate of CVE-2004-1448.    Medium  2017-01-07  2008-11-15  View

Page 15385 of 17672, showing 5 records out of 88360 total, starting on record 76921, ending on 76925

Actions