Записи dotproject
15 опубликованных записей вендора dotproject.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2002-1428Proof of concept | index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1dotproject · dotproject | Критическая10,0 | — | 5,5 % | 11 апр. 2003 г. |
32Наблюдать | CVE-2006-4234Proof of concept | PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrdotproject · dotproject | Высокая7,5 | — | 6,4 % | 18 авг. 2006 г. |
27Наблюдать | CVE-2008-6747Эксплойта нет | dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges.dotproject · dotproject · CWE-264 | Средняя6,8 | — | 1,2 % | 23 апр. 2009 г. |
27Наблюдать | CVE-2012-5701Proof of concept | Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commanddotproject · dotproject · CWE-89 | Средняя6,8 | — | 0,7 % | 20 окт. 2014 г. |
25Наблюдать | CVE-2007-5486Эксплойта нет | dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this modotproject · dotproject · CWE-264 | Средняя6,4 | — | 1,2 % | 16 окт. 2007 г. |
24Наблюдать | CVE-2006-0755Proof of concept | Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers tdotproject · dotproject | Средняя5,6 | — | 8,0 % | 17 февр. 2006 г. |
24Наблюдать | CVE-2008-3887Эксплойта нет | Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commandotproject · dotproject · CWE-89 | Средняя6,0 | — | 0,9 % | 2 сент. 2008 г. |
21Наблюдать | CVE-2006-0756Эксплойта нет | dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allowsdotproject · dotproject | Средняя5,0 | — | 2,2 % | 17 февр. 2006 г. |
21Наблюдать | CVE-2006-0754Эксплойта нет | dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain dotproject · dotproject | Средняя5,0 | — | 1,8 % | 17 февр. 2006 г. |
20Наблюдать | CVE-2011-3729Эксплойта нет | dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installationdotproject · dotproject · CWE-200 | Средняя5,0 | — | 1,3 % | 23 сент. 2011 г. |
18Наблюдать | CVE-2006-3240Эксплойта нет | Cross-site scripting (XSS) vulnerability in classes/ui.class.php in dotProject 2.0.3 and earlier allows remote attackers to inject arbitrarydotproject · dotproject · CWE-79 | Средняя4,3 | — | 2,3 % | 27 июн. 2006 г. |
18Наблюдать | CVE-2012-5702Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTMLdotproject · dotproject · CWE-79 | Средняя4,3 | — | 2,1 % | 21 окт. 2014 г. |
17Наблюдать | CVE-2006-2851Эксплойта нет | Cross-site scripting (XSS) vulnerability in index.php in dotProject 2.0.2 and earlier allows remote attackers to inject arbitrary web scriptdotproject · dotproject | Средняя4,3 | — | 1,4 % | 6 июн. 2006 г. |
17Наблюдать | CVE-2007-3226Эксплойта нет | Cross-site scripting (XSS) vulnerability in dotProject before 2.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unsdotproject · dotproject | Средняя4,3 | — | 1,3 % | 14 июн. 2007 г. |
17Наблюдать | CVE-2008-3886Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script odotproject · dotproject · CWE-79 | Средняя4,3 | — | 1,1 % | 2 сент. 2008 г. |
- CVE-2002-142842В плане
index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1
КритическаяCVSS 10,0Proof of conceptEPSS 6 %dotproject · dotproject11 апр. 2003 г.
- CVE-2006-423432Наблюдать
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitr
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %dotproject · dotproject18 авг. 2006 г.
- CVE-2008-674727Наблюдать
dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges.
СредняяCVSS 6,8Эксплойта нетEPSS 1 %dotproject · dotproject23 апр. 2009 г.
- CVE-2012-570127Наблюдать
Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL command
СредняяCVSS 6,8Proof of conceptEPSS 1 %dotproject · dotproject20 окт. 2014 г.
- CVE-2007-548625Наблюдать
dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this mo
СредняяCVSS 6,4Эксплойта нетEPSS 1 %dotproject · dotproject16 окт. 2007 г.
- CVE-2006-075524Наблюдать
Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers t
СредняяCVSS 5,6Proof of conceptEPSS 8 %dotproject · dotproject17 февр. 2006 г.
- CVE-2008-388724Наблюдать
Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL comman
СредняяCVSS 6,0Эксплойта нетEPSS 1 %dotproject · dotproject2 сент. 2008 г.
- CVE-2006-075621Наблюдать
dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows
СредняяCVSS 5,0Эксплойта нетEPSS 2 %dotproject · dotproject17 февр. 2006 г.
- CVE-2006-075421Наблюдать
dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain
СредняяCVSS 5,0Эксплойта нетEPSS 2 %dotproject · dotproject17 февр. 2006 г.
- CVE-2011-372920Наблюдать
dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
СредняяCVSS 5,0Эксплойта нетEPSS 1 %dotproject · dotproject23 сент. 2011 г.
- CVE-2006-324018Наблюдать
Cross-site scripting (XSS) vulnerability in classes/ui.class.php in dotProject 2.0.3 and earlier allows remote attackers to inject arbitrary
СредняяCVSS 4,3Эксплойта нетEPSS 2 %dotproject · dotproject27 июн. 2006 г.
- CVE-2012-570218Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Proof of conceptEPSS 2 %dotproject · dotproject21 окт. 2014 г.
- CVE-2006-285117Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in dotProject 2.0.2 and earlier allows remote attackers to inject arbitrary web script
СредняяCVSS 4,3Эксплойта нетEPSS 1 %dotproject · dotproject6 июн. 2006 г.
- CVE-2007-322617Наблюдать
Cross-site scripting (XSS) vulnerability in dotProject before 2.1 RC2 allows remote attackers to inject arbitrary web script or HTML via uns
СредняяCVSS 4,3Эксплойта нетEPSS 1 %dotproject · dotproject14 июн. 2007 г.
- CVE-2008-388617Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script o
СредняяCVSS 4,3Эксплойта нетEPSS 1 %dotproject · dotproject2 сент. 2008 г.