NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
40822  CVE-2013-5539  The upload-dialog implementation in Cisco Identity Services Engine (ISE) allows remote authenticated users to upload files with an arbitrary file type, and consequently conduct attacks against unspecified other systems, via a crafted file, aka Bug ID CSCui67511.    Medium  2017-01-18  2013-10-16  View
3610  CVE-2008-3745  The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via unspecified vectors.    5.5  Medium  2017-01-03  2011-03-07  View
14512  CVE-2010-3092  The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.    5.5  Medium  2017-01-18  2010-09-22  View
14040  CVE-2010-2584  The Upload method in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls does not properly restrict certain property values, which allows remote attackers to read arbitrary files via a filename in the SourceFile property in conjunction with an http URL in the DestURL property.    Medium  2017-01-18  2010-10-28  View
80710  CVE-2002-1759  The upload function in PHProjekt 2.0 through 3.1 does not properly verify certain variables related to uploaded data, which allows remote attackers to cause PHProjekt to process arbitrary files.    Medium  2017-07-18  2017-07-11  View

Page 2844 of 17672, showing 5 records out of 88360 total, starting on record 14216, ending on 14220

Actions