NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
58663  CVE-2007-6668  admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestricted file uploads, as demonstrated by uploading (1) a .php file and (2) a .php%00.jpeg file.    7.5  High  2017-01-07  2008-11-15  View
65421  CVE-2006-6878  admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] parameter to 1 during a login action.    7.5  High  2016-12-20  2011-03-07  View
10756  CVE-2011-4287  admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user.    6.8  Medium  2017-01-07  2012-07-16  View
57306  CVE-2007-5230  admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administrative actions via a direct request. NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231.    7.5  High  2017-01-07  2008-09-05  View
61380  CVE-2006-2695  admin/upprocess.php in DGNews 1.5 and earlier allows remote attackers to execute arbitrary code by uploading scripts with arbitrary extensions to the img directory.    5.1  Medium  2016-12-20  2013-09-10  View

Page 630 of 17672, showing 5 records out of 88360 total, starting on record 3146, ending on 3150

Actions