NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 58474 | CVE-2007-6479 | Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/. | 2 | 4.9 | Medium | 2017-01-07 | 2008-09-05 | View | |
| 83565 | CVE-2015-3884 | Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pages in qdPM 8.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/attachments/ or uploads/users/. | 2017-03-18 | 2017-03-17 | View | ||||
| 6940 | CVE-2008-7209 | Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arbitrary code by uploading a file with an executable extension and using a safe content type such as image/gif, then accessing it via a direct request to the file in an unspecified directory. | 2 | 7.5 | High | 2017-01-03 | 2009-09-15 | View | |
| 63214 | CVE-2006-4581 | Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts. | 2 | 5 | Medium | 2016-12-20 | 2008-11-15 | View | |
| 73067 | CVE-2004-2690 | Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execute arbitrary code instead of video files. | 2 | 8.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 15402 of 17672, showing 5 records out of 88360 total, starting on record 77006, ending on 77010