NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
58474  CVE-2007-6479  Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/.    4.9  Medium  2017-01-07  2008-09-05  View
83565  CVE-2015-3884  Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pages in qdPM 8.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/attachments/ or uploads/users/.          2017-03-18  2017-03-17  View
6940  CVE-2008-7209  Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arbitrary code by uploading a file with an executable extension and using a safe content type such as image/gif, then accessing it via a direct request to the file in an unspecified directory.    7.5  High  2017-01-03  2009-09-15  View
63214  CVE-2006-4581  Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts.    Medium  2016-12-20  2008-11-15  View
73067  CVE-2004-2690  Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execute arbitrary code instead of video files.    8.5  High  2016-12-20  2008-09-05  View

Page 15402 of 17672, showing 5 records out of 88360 total, starting on record 77006, ending on 77010

Actions