Skip to content
Noroxi

ProjectPier records

9 published records for vendor projectpier.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

9 records
  • PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbit

    CriticalCVSS 9.8No exploitEPSS 2%

    projectpier · projectpierMay 16, 2018

  • Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbi

    HighCVSS 8.8No exploitEPSS 1%

    projectpier · projectpierMay 16, 2018

  • CVE-2008-5583
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as an

    MediumCVSS 6.8No exploitEPSS 1%

    projectpier · projectpierDec 15, 2008

  • CVE-2015-2796
    24Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject arbitrary web script o

    MediumCVSS 6.1No exploitEPSS 1%

    projectpier · projectpierFeb 2, 2018

  • CVE-2013-3636
    21Monitor

    ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag

    MediumCVSS 5.4No exploitEPSS 1%

    projectpier · projectpierFeb 7, 2020

  • CVE-2013-3635
    21Monitor

    ProjectPier 0.8.8 has stored XSS

    MediumCVSS 5.4No exploitEPSS 1%

    projectpier · projectpierFeb 7, 2020

  • CVE-2013-3637
    21Monitor

    ProjectPier 0.8.8 does not use the Secure flag for cookies

    MediumCVSS 5.4No exploitEPSS 1%

    projectpier · projectpierFeb 7, 2020

  • CVE-2011-3797
    20Monitor

    ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installat

    MediumCVSS 5.0No exploitEPSS 1%

    projectpier · projectpierSep 23, 2011

  • CVE-2008-5584
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or

    MediumCVSS 4.3Proof of conceptEPSS 3%

    projectpier · projectpierDec 15, 2008