Перейти к содержимому
Noroxi

Записи dotproject

15 опубликованных записей вендора dotproject.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Все записи

    15 записей
    • CVE-2002-1428
      42В плане

      index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1

      КритическаяCVSS 10,0Proof of conceptEPSS 6 %

      dotproject · dotproject11 апр. 2003 г.

    • CVE-2006-4234
      32Наблюдать

      PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitr

      ВысокаяCVSS 7,5Proof of conceptEPSS 6 %

      dotproject · dotproject18 авг. 2006 г.

    • CVE-2008-6747
      27Наблюдать

      dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges.

      СредняяCVSS 6,8Эксплойта нетEPSS 1 %

      dotproject · dotproject23 апр. 2009 г.

    • CVE-2012-5701
      27Наблюдать

      Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL command

      СредняяCVSS 6,8Proof of conceptEPSS 1 %

      dotproject · dotproject20 окт. 2014 г.

    • CVE-2007-5486
      25Наблюдать

      dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this mo

      СредняяCVSS 6,4Эксплойта нетEPSS 1 %

      dotproject · dotproject16 окт. 2007 г.

    • CVE-2006-0755
      24Наблюдать

      Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers t

      СредняяCVSS 5,6Proof of conceptEPSS 8 %

      dotproject · dotproject17 февр. 2006 г.

    • CVE-2008-3887
      24Наблюдать

      Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL comman

      СредняяCVSS 6,0Эксплойта нетEPSS 1 %

      dotproject · dotproject2 сент. 2008 г.

    • CVE-2006-0756
      21Наблюдать

      dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows

      СредняяCVSS 5,0Эксплойта нетEPSS 2 %

      dotproject · dotproject17 февр. 2006 г.

    • CVE-2006-0754
      21Наблюдать

      dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain

      СредняяCVSS 5,0Эксплойта нетEPSS 2 %

      dotproject · dotproject17 февр. 2006 г.

    • CVE-2011-3729
      20Наблюдать

      dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation

      СредняяCVSS 5,0Эксплойта нетEPSS 1 %

      dotproject · dotproject23 сент. 2011 г.

    • CVE-2006-3240
      18Наблюдать

      Cross-site scripting (XSS) vulnerability in classes/ui.class.php in dotProject 2.0.3 and earlier allows remote attackers to inject arbitrary

      СредняяCVSS 4,3Эксплойта нетEPSS 2 %

      dotproject · dotproject27 июн. 2006 г.

    • CVE-2012-5702
      18Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML

      СредняяCVSS 4,3Proof of conceptEPSS 2 %

      dotproject · dotproject21 окт. 2014 г.

    • CVE-2006-2851
      17Наблюдать

      Cross-site scripting (XSS) vulnerability in index.php in dotProject 2.0.2 and earlier allows remote attackers to inject arbitrary web script

      СредняяCVSS 4,3Эксплойта нетEPSS 1 %

      dotproject · dotproject6 июн. 2006 г.

    • CVE-2007-3226
      17Наблюдать

      Cross-site scripting (XSS) vulnerability in dotProject before 2.1 RC2 allows remote attackers to inject arbitrary web script or HTML via uns

      СредняяCVSS 4,3Эксплойта нетEPSS 1 %

      dotproject · dotproject14 июн. 2007 г.

    • CVE-2008-3886
      17Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script o

      СредняяCVSS 4,3Эксплойта нетEPSS 1 %

      dotproject · dotproject2 сент. 2008 г.