ProjectPier kayıtları
projectpier üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-10759İstismar yok | PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitprojectpier · projectpier · CWE-89 | Kritik9,8 | — | %1,8 | 16 May 2018 |
35İzleyin | CVE-2018-10760İstismar yok | Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbiprojectpier · projectpier · CWE-434 | Yüksek8,8 | — | %1,2 | 16 May 2018 |
27İzleyin | CVE-2008-5583İstismar yok | Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as anprojectpier · projectpier · CWE-352 | Orta6,8 | — | %0,7 | 15 Ara 2008 |
24İzleyin | CVE-2015-2796İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject arbitrary web script oprojectpier · projectpier · CWE-79 | Orta6,1 | — | %1,1 | 2 Şub 2018 |
21İzleyin | CVE-2013-3636İstismar yok | ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flagprojectpier · projectpier · CWE-79 | Orta5,4 | — | %1,0 | 7 Şub 2020 |
21İzleyin | CVE-2013-3635İstismar yok | ProjectPier 0.8.8 has stored XSSprojectpier · projectpier · CWE-79 | Orta5,4 | — | %0,6 | 7 Şub 2020 |
21İzleyin | CVE-2013-3637İstismar yok | ProjectPier 0.8.8 does not use the Secure flag for cookiesprojectpier · projectpier · CWE-79 | Orta5,4 | — | %0,6 | 7 Şub 2020 |
20İzleyin | CVE-2011-3797İstismar yok | ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatprojectpier · projectpier · CWE-200 | Orta5,0 | — | %1,2 | 23 Eyl 2011 |
18İzleyin | CVE-2008-5584Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or projectpier · projectpier · CWE-79 | Orta4,3 | — | %3,0 | 15 Ara 2008 |
- CVE-2018-1075940Planlayın
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbit
KritikCVSS 9,8İstismar yokEPSS %2projectpier · projectpier16 May 2018
- CVE-2018-1076035İzleyin
Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbi
YüksekCVSS 8,8İstismar yokEPSS %1projectpier · projectpier16 May 2018
- CVE-2008-558327İzleyin
Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as an
OrtaCVSS 6,8İstismar yokEPSS %1projectpier · projectpier15 Ara 2008
- CVE-2015-279624İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject arbitrary web script o
OrtaCVSS 6,1İstismar yokEPSS %1projectpier · projectpier2 Şub 2018
- CVE-2013-363621İzleyin
ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag
OrtaCVSS 5,4İstismar yokEPSS %1projectpier · projectpier7 Şub 2020
- CVE-2013-363521İzleyin
ProjectPier 0.8.8 has stored XSS
OrtaCVSS 5,4İstismar yokEPSS %1projectpier · projectpier7 Şub 2020
- CVE-2013-363721İzleyin
ProjectPier 0.8.8 does not use the Secure flag for cookies
OrtaCVSS 5,4İstismar yokEPSS %1projectpier · projectpier7 Şub 2020
- CVE-2011-379720İzleyin
ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installat
OrtaCVSS 5,0İstismar yokEPSS %1projectpier · projectpier23 Eyl 2011
- CVE-2008-558418İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or
OrtaCVSS 4,3Kavram kanıtıEPSS %3projectpier · projectpier15 Ara 2008