Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Joomla\! MEDIUM 6.5
CVE-2006-4471

The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ direc…

Fix: 1.0.11+
Fix from $1,600 2006-08-31
Duware Dubanner HIGH 7.5
CVE-2006-2428

add.asp in DUware DUbanner 3.1 allows remote attackers to execute arbitrary code by uploading files with arbitrary extensions, such as ASP files, pro…

Mitigation only
Fix from $1,950 2006-05-17
Mailsite Express MEDIUM 5.0
CVE-2005-3288

Mailsite Express allows remote attackers to upload and execute files with executable extensions such as ASP by attaching the file using the "compose …

Patch available
Fix from $1,600 2005-10-23
I Man HIGH 7.5
CVE-2005-1868

I-Man 0.9, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by uploading a file attachment with a .php extension.

Fix: after 0.9
Fix from $1,950 2005-06-09
Yapig HIGH 7.5
CVE-2005-1881

upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to u…

No fix yet
Fix from $1,950 2005-06-06
E107 HIGH 7.5
CVE-2004-2262EPSS 15%

ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by upl…

Fix: 0.617+
Fix from $1,950 2004-12-31
Nola MEDIUM 5.0
CVE-2002-1841

The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to uploa…

Patch available
Fix from $1,600 2002-12-31
Hypermail HIGH 7.5
CVE-2001-0901

Hypermail allows remote attackers to execute arbitrary commands on a server supporting SSI via an attachment with a .shtml extension, which is archiv…

Mitigation only
Fix from $1,950 2001-11-19
Norton Antivirus MEDIUM 5.0
CVE-2001-1099

The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by …

No fix yet
Fix from $1,600 2001-09-07
Exchange Server HIGH 7.5
CVE-2001-0340EPSS 6%

An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malic…

Patch available
Fix from $1,950 2001-07-21
Irix HIGH 8.4
CVE-1999-0036

IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.

Mitigation only
Fix from $1,950 1997-05-26