Show filters
51 Total Results
Displaying 41-50 of 51
Sort by:
Attacker Value
Unknown

CVE-2008-2110

Disclosure Date: May 07, 2008 (last updated October 04, 2023)
Unrestricted file upload vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request.
0
Attacker Value
Unknown

CVE-2008-0222

Disclosure Date: January 10, 2008 (last updated October 04, 2023)
Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-4117

Disclosure Date: August 01, 2007 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in index.php in phpWebFileManager 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the PN_PathPrefix parameter. NOTE: this issue is disputed by a reliable third party, who demonstrates that PN_PathPrefix is defined before use
0
Attacker Value
Unknown

CVE-2007-0252

Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Unspecified vulnerability in easy-content filemanager allows remote attackers to upload or modify arbitrary files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2006-3987

Disclosure Date: August 05, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) dwl_download_path or (2) dwl_include_path parameters.
0
Attacker Value
Unknown

CVE-2006-3405

Disclosure Date: July 07, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters.
0
Attacker Value
Unknown

CVE-2006-3406

Disclosure Date: July 07, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to modify arbitrary files via a .. (dot dot) sequence in the edit parameter.
0
Attacker Value
Unknown

CVE-2006-3132

Disclosure Date: June 22, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in qtofm.php4 in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, as originally reported for index.php.
0
Attacker Value
Unknown

CVE-2004-2047

Disclosure Date: July 23, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter.
0
Attacker Value
Unknown

CVE-2003-1542

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.
0