NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 1894 | CVE-2008-1958 | Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with a .php extension. | 2 | 6.5 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 40065 | CVE-2013-4465 | Unrestricted file upload vulnerability in the avatar upload functionality in Simple Machines Forum before 2.0.6 and 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory. | 2 | 4.6 | Medium | 2017-01-18 | 2013-10-28 | View | |
| 24251 | CVE-2015-2087 | Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors. | 2 | 6.5 | Medium | 2017-01-19 | 2015-02-27 | View | |
| 22339 | CVE-2016-9268 | Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors. | 2 | 9 | High | 2017-01-19 | 2016-11-29 | View | |
| 3607 | CVE-2008-3742 | Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, which is not validated. | 2 | 6.5 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 15403 of 17672, showing 5 records out of 88360 total, starting on record 77011, ending on 77015