Записи ProjectPier
9 опубликованных записей вендора projectpier.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-10759Эксплойта нет | PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitprojectpier · projectpier · CWE-89 | Критическая9,8 | — | 1,8 % | 16 мая 2018 г. |
35Наблюдать | CVE-2018-10760Эксплойта нет | Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbiprojectpier · projectpier · CWE-434 | Высокая8,8 | — | 1,2 % | 16 мая 2018 г. |
27Наблюдать | CVE-2008-5583Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as anprojectpier · projectpier · CWE-352 | Средняя6,8 | — | 0,7 % | 15 дек. 2008 г. |
24Наблюдать | CVE-2015-2796Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject arbitrary web script oprojectpier · projectpier · CWE-79 | Средняя6,1 | — | 1,1 % | 2 февр. 2018 г. |
21Наблюдать | CVE-2013-3636Эксплойта нет | ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flagprojectpier · projectpier · CWE-79 | Средняя5,4 | — | 1,0 % | 7 февр. 2020 г. |
21Наблюдать | CVE-2013-3635Эксплойта нет | ProjectPier 0.8.8 has stored XSSprojectpier · projectpier · CWE-79 | Средняя5,4 | — | 0,6 % | 7 февр. 2020 г. |
21Наблюдать | CVE-2013-3637Эксплойта нет | ProjectPier 0.8.8 does not use the Secure flag for cookiesprojectpier · projectpier · CWE-79 | Средняя5,4 | — | 0,6 % | 7 февр. 2020 г. |
20Наблюдать | CVE-2011-3797Эксплойта нет | ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatprojectpier · projectpier · CWE-200 | Средняя5,0 | — | 1,2 % | 23 сент. 2011 г. |
18Наблюдать | CVE-2008-5584Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or projectpier · projectpier · CWE-79 | Средняя4,3 | — | 3,0 % | 15 дек. 2008 г. |
- CVE-2018-1075940В плане
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbit
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %projectpier · projectpier16 мая 2018 г.
- CVE-2018-1076035Наблюдать
Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %projectpier · projectpier16 мая 2018 г.
- CVE-2008-558327Наблюдать
Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as an
СредняяCVSS 6,8Эксплойта нетEPSS 1 %projectpier · projectpier15 дек. 2008 г.
- CVE-2015-279624Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject arbitrary web script o
СредняяCVSS 6,1Эксплойта нетEPSS 1 %projectpier · projectpier2 февр. 2018 г.
- CVE-2013-363621Наблюдать
ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag
СредняяCVSS 5,4Эксплойта нетEPSS 1 %projectpier · projectpier7 февр. 2020 г.
- CVE-2013-363521Наблюдать
ProjectPier 0.8.8 has stored XSS
СредняяCVSS 5,4Эксплойта нетEPSS 1 %projectpier · projectpier7 февр. 2020 г.
- CVE-2013-363721Наблюдать
ProjectPier 0.8.8 does not use the Secure flag for cookies
СредняяCVSS 5,4Эксплойта нетEPSS 1 %projectpier · projectpier7 февр. 2020 г.
- CVE-2011-379720Наблюдать
ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installat
СредняяCVSS 5,0Эксплойта нетEPSS 1 %projectpier · projectpier23 сент. 2011 г.
- CVE-2008-558418Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or
СредняяCVSS 4,3Proof of conceptEPSS 3 %projectpier · projectpier15 дек. 2008 г.