dotproject kayıtları
dotproject üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2002-1428Kavram kanıtı | index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1dotproject · dotproject | Kritik10,0 | — | %5,5 | 11 Nis 2003 |
32İzleyin | CVE-2006-4234Kavram kanıtı | PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrdotproject · dotproject | Yüksek7,5 | — | %6,4 | 18 Ağu 2006 |
27İzleyin | CVE-2008-6747İstismar yok | dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges.dotproject · dotproject · CWE-264 | Orta6,8 | — | %1,2 | 23 Nis 2009 |
27İzleyin | CVE-2012-5701Kavram kanıtı | Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commanddotproject · dotproject · CWE-89 | Orta6,8 | — | %0,7 | 20 Eki 2014 |
25İzleyin | CVE-2007-5486İstismar yok | dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this modotproject · dotproject · CWE-264 | Orta6,4 | — | %1,2 | 16 Eki 2007 |
24İzleyin | CVE-2006-0755Kavram kanıtı | Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers tdotproject · dotproject | Orta5,6 | — | %8,0 | 17 Şub 2006 |
24İzleyin | CVE-2008-3887İstismar yok | Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commandotproject · dotproject · CWE-89 | Orta6,0 | — | %0,9 | 2 Eyl 2008 |
21İzleyin | CVE-2006-0756İstismar yok | dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allowsdotproject · dotproject | Orta5,0 | — | %2,2 | 17 Şub 2006 |
21İzleyin | CVE-2006-0754İstismar yok | dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain dotproject · dotproject | Orta5,0 | — | %1,8 | 17 Şub 2006 |
20İzleyin | CVE-2011-3729İstismar yok | dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installationdotproject · dotproject · CWE-200 | Orta5,0 | — | %1,3 | 23 Eyl 2011 |
18İzleyin | CVE-2006-3240İstismar yok | Cross-site scripting (XSS) vulnerability in classes/ui.class.php in dotProject 2.0.3 and earlier allows remote attackers to inject arbitrarydotproject · dotproject · CWE-79 | Orta4,3 | — | %2,3 | 27 Haz 2006 |
18İzleyin | CVE-2012-5702Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTMLdotproject · dotproject · CWE-79 | Orta4,3 | — | %2,1 | 21 Eki 2014 |
17İzleyin | CVE-2006-2851İstismar yok | Cross-site scripting (XSS) vulnerability in index.php in dotProject 2.0.2 and earlier allows remote attackers to inject arbitrary web scriptdotproject · dotproject | Orta4,3 | — | %1,4 | 6 Haz 2006 |
17İzleyin | CVE-2007-3226İstismar yok | Cross-site scripting (XSS) vulnerability in dotProject before 2.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unsdotproject · dotproject | Orta4,3 | — | %1,3 | 14 Haz 2007 |
17İzleyin | CVE-2008-3886İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script odotproject · dotproject · CWE-79 | Orta4,3 | — | %1,1 | 2 Eyl 2008 |
- CVE-2002-142842Planlayın
index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1
KritikCVSS 10,0Kavram kanıtıEPSS %6dotproject · dotproject11 Nis 2003
- CVE-2006-423432İzleyin
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitr
YüksekCVSS 7,5Kavram kanıtıEPSS %6dotproject · dotproject18 Ağu 2006
- CVE-2008-674727İzleyin
dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges.
OrtaCVSS 6,8İstismar yokEPSS %1dotproject · dotproject23 Nis 2009
- CVE-2012-570127İzleyin
Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL command
OrtaCVSS 6,8Kavram kanıtıEPSS %1dotproject · dotproject20 Eki 2014
- CVE-2007-548625İzleyin
dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this mo
OrtaCVSS 6,4İstismar yokEPSS %1dotproject · dotproject16 Eki 2007
- CVE-2006-075524İzleyin
Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers t
OrtaCVSS 5,6Kavram kanıtıEPSS %8dotproject · dotproject17 Şub 2006
- CVE-2008-388724İzleyin
Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL comman
OrtaCVSS 6,0İstismar yokEPSS %1dotproject · dotproject2 Eyl 2008
- CVE-2006-075621İzleyin
dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows
OrtaCVSS 5,0İstismar yokEPSS %2dotproject · dotproject17 Şub 2006
- CVE-2006-075421İzleyin
dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain
OrtaCVSS 5,0İstismar yokEPSS %2dotproject · dotproject17 Şub 2006
- CVE-2011-372920İzleyin
dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
OrtaCVSS 5,0İstismar yokEPSS %1dotproject · dotproject23 Eyl 2011
- CVE-2006-324018İzleyin
Cross-site scripting (XSS) vulnerability in classes/ui.class.php in dotProject 2.0.3 and earlier allows remote attackers to inject arbitrary
OrtaCVSS 4,3İstismar yokEPSS %2dotproject · dotproject27 Haz 2006
- CVE-2012-570218İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML
OrtaCVSS 4,3Kavram kanıtıEPSS %2dotproject · dotproject21 Eki 2014
- CVE-2006-285117İzleyin
Cross-site scripting (XSS) vulnerability in index.php in dotProject 2.0.2 and earlier allows remote attackers to inject arbitrary web script
OrtaCVSS 4,3İstismar yokEPSS %1dotproject · dotproject6 Haz 2006
- CVE-2007-322617İzleyin
Cross-site scripting (XSS) vulnerability in dotProject before 2.1 RC2 allows remote attackers to inject arbitrary web script or HTML via uns
OrtaCVSS 4,3İstismar yokEPSS %1dotproject · dotproject14 Haz 2007
- CVE-2008-388617İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script o
OrtaCVSS 4,3İstismar yokEPSS %1dotproject · dotproject2 Eyl 2008