VYPR

E-Uploader Pro

by E Uploader

CVEs (3)

  • CVE-2009-2180Jun 23, 2009
    risk 0.03cvss epss 0.06

    Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the file parameter.

  • CVE-2008-5075Nov 14, 2008
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in E-Uploader Pro 1.0 (aka Uploader PRO), when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) img.php, (b) file.php, (c) mail.php, (d) thumb.php, (e) zip.php, and (f)…

  • CVE-2006-6694Dec 21, 2006
    risk 0.03cvss epss 0.02

    Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a .. (dot dot) in the language parameter, as demonstrated by uploading a .JPG file containing PHP code, then accessing the file via…