NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64923 | CVE-2006-6377 | Uploadscript 1.2 and earlier stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain the admin password hash via a direct request for /password.txt. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
56068 | CVE-2007-3932 | uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows remote attackers to upload and execute arbitrary PHP code in the img/ folder. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
58522 | CVE-2007-6527 | uploadimg.php in the Automatic Image Upload with Thumbnails (imgUpload) module 1.3.2 for PunBB only verifies the Content-type field of uploaded files, which allows remote attackers to upload and execute arbitrary content via a file with a (1) JPG, (2) GIF, or (3) PNG MIME type. | 2 | 5.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
71924 | CVE-2004-1545 | UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
6344 | CVE-2008-6613 | uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request. | 2 | 7.5 | High | 2017-01-03 | 2009-04-06 | View |
Page 891 of 17672, showing 5 records out of 88360 total, starting on record 4451, ending on 4455