Vulnerabilities (CVE)

Filtered by vendor Qto Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-2110 1 Qto 1 Qtofilemanager 2024-02-28 7.5 HIGH N/A
Unrestricted file upload vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request.
CVE-2006-3132 1 Qto 1 Qtofilemanager 2024-02-28 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in qtofm.php4 in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, as originally reported for index.php.
CVE-2006-3406 1 Qto 1 Qtofilemanager 2024-02-28 6.4 MEDIUM N/A
Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to modify arbitrary files via a .. (dot dot) sequence in the edit parameter.
CVE-2006-3405 1 Qto 1 Qtofilemanager 2024-02-28 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters.