flyspray records
10 published records for vendor flyspray.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 10%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
27Monitor | CVE-2007-1788No exploit | Flyspray 0.9.9, when output_buffering is disabled or "set to a low value," allows remote attackers to bypass authentication via a crafted poflyspray · flyspray | Medium6.8 | — | 1.3% | Mar 31, 2007 |
27Monitor | CVE-2007-1789No exploit | Flyspray 0.9.9 allows remote attackers to obtain sensitive information (private project summaries) via direct requests.flyspray · flyspray | Medium6.8 | — | 1.2% | Mar 31, 2007 |
24Monitor | CVE-2012-1058Proof of concept | Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requeflyspray · flyspray · CWE-352 | Medium6.0 | — | 0.9% | Feb 13, 2012 |
22Monitor | CVE-2006-0714Proof of concept | Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbiflyspray · flyspray | Medium5.0 | — | 7.8% | Feb 15, 2006 |
21Monitor | CVE-2017-15214No exploit | Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privilegflyspray · flyspray · CWE-79 | Medium5.4 | — | 0.9% | Oct 10, 2017 |
21Monitor | CVE-2017-15213No exploit | Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via flyspray · flyspray · CWE-79 | Medium5.4 | — | 0.8% | Oct 10, 2017 |
20Monitor | CVE-2008-1166No exploit | Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to flyspray · flyspray · CWE-200 | Medium5.0 | — | 1.2% | Mar 5, 2008 |
18Monitor | CVE-2005-3334Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary weflyspray · flyspray | Medium4.3 | — | 4.6% | Oct 27, 2005 |
17Monitor | CVE-2007-6461No exploit | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flyspray 0.9.9 through 0.9.9.3 allow remote attackers to inject arbitrarflyspray · flyspray · CWE-79 | Medium4.3 | — | 1.1% | Dec 19, 2007 |
17Monitor | CVE-2008-1165No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Flyspray 0.9.9 through 0.9.9.4 allow remote attackers to inject arbitrary web script flyspray · flyspray · CWE-79 | Medium4.3 | — | 1.0% | Mar 5, 2008 |
- CVE-2007-178827Monitor
Flyspray 0.9.9, when output_buffering is disabled or "set to a low value," allows remote attackers to bypass authentication via a crafted po
MediumCVSS 6.8No exploitEPSS 1%flyspray · flysprayMar 31, 2007
- CVE-2007-178927Monitor
Flyspray 0.9.9 allows remote attackers to obtain sensitive information (private project summaries) via direct requests.
MediumCVSS 6.8No exploitEPSS 1%flyspray · flysprayMar 31, 2007
- CVE-2012-105824Monitor
Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for reque
MediumCVSS 6.0Proof of conceptEPSS 1%flyspray · flysprayFeb 13, 2012
- CVE-2006-071422Monitor
Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbi
MediumCVSS 5.0Proof of conceptEPSS 8%flyspray · flysprayFeb 15, 2006
- CVE-2017-1521421Monitor
Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileg
MediumCVSS 5.4No exploitEPSS 1%flyspray · flysprayOct 10, 2017
- CVE-2017-1521321Monitor
Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via
MediumCVSS 5.4No exploitEPSS 1%flyspray · flysprayOct 10, 2017
- CVE-2008-116620Monitor
Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to
MediumCVSS 5.0No exploitEPSS 1%flyspray · flysprayMar 5, 2008
- CVE-2005-333418Monitor
Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary we
MediumCVSS 4.3Proof of conceptEPSS 5%flyspray · flysprayOct 27, 2005
- CVE-2007-646117Monitor
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flyspray 0.9.9 through 0.9.9.3 allow remote attackers to inject arbitrar
MediumCVSS 4.3No exploitEPSS 1%flyspray · flysprayDec 19, 2007
- CVE-2008-116517Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Flyspray 0.9.9 through 0.9.9.4 allow remote attackers to inject arbitrary web script
MediumCVSS 4.3No exploitEPSS 1%flyspray · flysprayMar 5, 2008