NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
58663 | CVE-2007-6668 | admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestricted file uploads, as demonstrated by uploading (1) a .php file and (2) a .php%00.jpeg file. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
65421 | CVE-2006-6878 | admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] parameter to 1 during a login action. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
10756 | CVE-2011-4287 | admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user. | 2 | 6.8 | Medium | 2017-01-07 | 2012-07-16 | View | |
57306 | CVE-2007-5230 | admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administrative actions via a direct request. NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
61380 | CVE-2006-2695 | admin/upprocess.php in DGNews 1.5 and earlier allows remote attackers to execute arbitrary code by uploading scripts with arbitrary extensions to the img directory. | 2 | 5.1 | Medium | 2016-12-20 | 2013-09-10 | View |
Page 630 of 17672, showing 5 records out of 88360 total, starting on record 3146, ending on 3150