NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 63235 | CVE-2006-4602 | Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory. | 2 | 7.5 | High | 2016-12-20 | 2012-10-24 | View | |
| 1190 | CVE-2008-1230 | Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbitrary .jsp files via an unspecified manipulation that attaches a .jsp file to an "entry page." | 2 | 9.3 | High | 2017-01-03 | 2008-09-05 | View | |
| 5419 | CVE-2008-5677 | Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root, allows remote authenticated users with upload capability to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under items/, related to the ReplaceBadFilenameChars function in include/ItemAdder.php. NOTE: some of these details are obtained from third party information. | 2 | 7.1 | High | 2017-01-03 | 2009-01-29 | View | |
| 54906 | CVE-2007-2742 | Unrestricted file upload vulnerability in labs.beffa.org w2box 4.0.0 Beta4 allows remote attackers to upload arbitrary PHP code via a filename with a double extension such as .php.jpg. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 41175 | CVE-2013-5961 | Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/. | 2 | 6.8 | Medium | 2017-01-18 | 2013-10-11 | View |
Page 15386 of 17672, showing 5 records out of 88360 total, starting on record 76926, ending on 76930