Записи Qdpm
18 опубликованных записей вендора qdpm.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 11,1 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
60На этой неделе | CVE-2020-7246Готовый эксплойт | A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier.qdpm · qdpm · CWE-22 | Высокая8,8 | — | 83,2 % | 21 янв. 2020 г. |
40В плане | CVE-2020-11811Эксплойта нет | In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted contenqdpm · qdpm · CWE-434 | Критическая9,8 | — | 3,0 % | 16 апр. 2020 г. |
39Наблюдать | CVE-2015-3884Готовый эксплойт | Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) schqdpm · qdpm · CWE-434 | Высокая8,8 | — | 14,4 % | 17 мар. 2017 г. |
39Наблюдать | CVE-2023-45856Эксплойта нет | qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.qdpm · qdpm · CWE-434 | Критическая9,8 | — | 1,4 % | 14 окт. 2023 г. |
36Наблюдать | CVE-2022-26180Proof of concept | qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.qdpm · qdpm · CWE-352 | Высокая8,8 | — | 3,8 % | 8 апр. 2022 г. |
36Наблюдать | CVE-2020-26165Эксплойта нет | qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.classqdpm · qdpm · CWE-502 | Высокая8,8 | — | 2,5 % | 31 дек. 2020 г. |
35Наблюдать | CVE-2018-25208Эксплойта нет | qdPM 9.1 SQL Injection via filter_by Parametersqdpm · qdpm · CWE-89 | Высокая8,8 | — | 0,3 % | 26 мар. 2026 г. |
35Наблюдать | CVE-2019-25669Эксплойта нет | qdPM 9.1 SQL Injection via search_by_extrafields Parameterqdpm · qdpm · CWE-89 | Высокая8,8 | — | 0,3 % | 5 апр. 2026 г. |
31Наблюдать | CVE-2023-45855Proof of concept | qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.qdpm · qdpm · CWE-22 | Высокая7,5 | — | 3,3 % | 14 окт. 2023 г. |
30Наблюдать | CVE-2015-3881Эксплойта нет | Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/datqdpm · qdpm · CWE-200 | Высокая7,5 | — | 1,5 % | 17 мар. 2017 г. |
27Наблюдать | CVE-2019-8390Proof of concept | qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.qdpm · qdpm · CWE-79 | Средняя6,1 | — | 9,8 % | 14 мая 2019 г. |
25Наблюдать | CVE-2019-8391Proof of concept | qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.qdpm · qdpm · CWE-79 | Средняя6,1 | — | 3,3 % | 14 мая 2019 г. |
25Наблюдать | CVE-2020-19515Proof of concept | qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.qdpm · qdpm · CWE-79 | Средняя6,1 | — | 1,8 % | 9 сент. 2021 г. |
24Наблюдать | CVE-2015-3883Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) seqdpm · qdpm · CWE-79 | Средняя6,1 | — | 0,8 % | 17 мар. 2017 г. |
21Наблюдать | CVE-2015-3882Эксплойта нет | qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the insqdpm · qdpm · CWE-200 | Средняя5,3 | — | 1,2 % | 17 мар. 2017 г. |
21Наблюдать | CVE-2020-11814Эксплойта нет | A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious websiteqdpm · qdpm · CWE-74 | Средняя5,4 | — | 1,0 % | 16 апр. 2020 г. |
21Наблюдать | CVE-2020-26166Эксплойта нет | The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web scriqdpm · qdpm · CWE-79 | Средняя5,4 | — | 0,8 % | 5 окт. 2020 г. |
21Наблюдать | CVE-2020-18468Эксплойта нет | Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a cqdpm · qdpm · CWE-79 | Средняя5,4 | — | 0,4 % | 26 авг. 2021 г. |
- CVE-2020-724660На этой неделе
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 83 %qdpm · qdpm21 янв. 2020 г.
- CVE-2020-1181140В плане
In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted conten
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %qdpm · qdpm16 апр. 2020 г.
- CVE-2015-388439Наблюдать
Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) sch
ВысокаяCVSS 8,8Готовый эксплойтEPSS 14 %qdpm · qdpm17 мар. 2017 г.
- CVE-2023-4585639Наблюдать
qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qdpm · qdpm14 окт. 2023 г.
- CVE-2022-2618036Наблюдать
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %qdpm · qdpm8 апр. 2022 г.
- CVE-2020-2616536Наблюдать
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %qdpm · qdpm31 дек. 2020 г.
- CVE-2018-2520835Наблюдать
qdPM 9.1 SQL Injection via filter_by Parameters
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %qdpm · qdpm26 мар. 2026 г.
- CVE-2019-2566935Наблюдать
qdPM 9.1 SQL Injection via search_by_extrafields Parameter
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %qdpm · qdpm5 апр. 2026 г.
- CVE-2023-4585531Наблюдать
qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %qdpm · qdpm14 окт. 2023 г.
- CVE-2015-388130Наблюдать
Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/dat
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %qdpm · qdpm17 мар. 2017 г.
- CVE-2019-839027Наблюдать
qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
СредняяCVSS 6,1Proof of conceptEPSS 10 %qdpm · qdpm14 мая 2019 г.
- CVE-2019-839125Наблюдать
qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.
СредняяCVSS 6,1Proof of conceptEPSS 3 %qdpm · qdpm14 мая 2019 г.
- CVE-2020-1951525Наблюдать
qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
СредняяCVSS 6,1Proof of conceptEPSS 2 %qdpm · qdpm9 сент. 2021 г.
- CVE-2015-388324Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) se
СредняяCVSS 6,1Эксплойта нетEPSS 1 %qdpm · qdpm17 мар. 2017 г.
- CVE-2015-388221Наблюдать
qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the ins
СредняяCVSS 5,3Эксплойта нетEPSS 1 %qdpm · qdpm17 мар. 2017 г.
- CVE-2020-1181421Наблюдать
A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious website
СредняяCVSS 5,4Эксплойта нетEPSS 1 %qdpm · qdpm16 апр. 2020 г.
- CVE-2020-2616621Наблюдать
The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web scri
СредняяCVSS 5,4Эксплойта нетEPSS 1 %qdpm · qdpm5 окт. 2020 г.
- CVE-2020-1846821Наблюдать
Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a c
СредняяCVSS 5,4Эксплойта нетEPSS 0 %qdpm · qdpm26 авг. 2021 г.