projectsend kayıtları
projectsend üreticisine ait 29 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %3,4
- Silahlaştırılmış
- 2 · %6,9
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 7 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-287 Improper Authentication2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File2
- CWE-330 Use of Insufficiently Random Values1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
29 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
97Hemen | CVE-2024-11680Silahlaştırılmış | ProjectSend Unauthenticated Configuration Modificationprojectsend · projectsend · CWE-306 | Kritik9,8 | KEV | %91,7 | 26 Kas 2024 |
43Planlayın | CVE-2014-9567Silahlaştırılmış | Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to exeprojectsend · projectsend · CWE-94 | Yüksek7,5 | — | %43,3 | 7 Oca 2015 |
40Planlayın | CVE-2021-40887İstismar yok | Projectsend version r1295 is affected by a directory traversal vulnerability.projectsend · projectsend · CWE-22 | Kritik9,8 | — | %2,4 | 11 Eki 2021 |
40Planlayın | CVE-2016-10733İstismar yok | ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.projectsend · projectsend · CWE-22 | Kritik9,8 | — | %2,1 | 29 Eki 2018 |
40Planlayın | CVE-2016-10732İstismar yok | ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or procprojectsend · projectsend · CWE-287 | Kritik9,8 | — | %1,9 | 29 Eki 2018 |
39İzleyin | CVE-2017-9741İstismar yok | install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to repprojectsend · projectsend · CWE-20 | Kritik9,8 | — | %1,6 | 18 Haz 2017 |
39İzleyin | CVE-2016-10734İstismar yok | ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.projectsend · projectsend · CWE-285 | Kritik9,8 | — | %1,5 | 29 Eki 2018 |
39İzleyin | CVE-2016-10731İstismar yok | ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the requprojectsend · projectsend · CWE-89 | Kritik9,8 | — | %1,4 | 29 Eki 2018 |
36İzleyin | CVE-2019-11378İstismar yok | An issue was discovered in ProjectSend r1053.projectsend · projectsend · CWE-22 | Yüksek8,8 | — | %3,6 | 20 Nis 2019 |
35İzleyin | CVE-2018-7201İstismar yok | CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.projectsend · projectsend · CWE-1236 | Yüksek8,8 | — | %1,3 | 22 May 2019 |
34İzleyin | CVE-2023-53980İstismar yok | ProjectSend r1605 Remote Code Execution via File Extension Manipulationprojectsend · projectsend · CWE-434 | Yüksek8,7 | — | %0,9 | 22 Ara 2025 |
32İzleyin | CVE-2021-40884İstismar yok | Projectsend version r1295 is affected by sensitive information disclosure.projectsend · projectsend · CWE-862 | Yüksek8,1 | — | %1,0 | 11 Eki 2021 |
31İzleyin | CVE-2020-28874Kavram kanıtı | reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic.projectsend · projectsend · CWE-287 | Yüksek7,5 | — | %2,4 | 26 Oca 2021 |
30İzleyin | CVE-2019-11492İstismar yok | ProjectSend before r1070 writes user passwords to the server logs.projectsend · projectsend · CWE-532 | Yüksek7,5 | — | %1,1 | 26 Nis 2019 |
28İzleyin | CVE-2023-53930İstismar yok | ProjectSend r1605 Insecure Direct Object Reference File Download Vulnerabilityprojectsend · projectsend · CWE-639 | Yüksek7,1 | — | %0,4 | 17 Ara 2025 |
27İzleyin | CVE-2015-2564Kavram kanıtı | SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQprojectsend · projectsend · CWE-89 | Orta6,5 | — | %3,1 | 20 Mar 2015 |
27İzleyin | CVE-2024-7658İstismar yok | projectsend process.php get_preview resource injectionprojectsend · projectsend · CWE-99 | Orta6,9 | — | %0,8 | 12 Ağu 2024 |
26İzleyin | CVE-2021-40886İstismar yok | Projectsend version r1295 is affected by a directory traversal vulnerability.projectsend · projectsend · CWE-22 | Orta6,5 | — | %1,4 | 11 Eki 2021 |
25İzleyin | CVE-2024-7659İstismar yok | projectsend Password Reset Token functions.php generate_random_string random valuesprojectsend · projectsend · CWE-330 | Orta6,3 | — | %0,8 | 12 Ağu 2024 |
24İzleyin | CVE-2019-11533İstismar yok | Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web script or HTML.projectsend · projectsend · CWE-79 | Orta6,1 | — | %1,2 | 26 Nis 2019 |
24İzleyin | CVE-2017-9783İstismar yok | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remoteprojectsend · projectsend · CWE-79 | Orta6,1 | — | %1,1 | 6 Mar 2018 |
24İzleyin | CVE-2017-9786İstismar yok | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remoteprojectsend · projectsend · CWE-79 | Orta6,1 | — | %1,0 | 6 Mar 2018 |
24İzleyin | CVE-2018-7202İstismar yok | An issue was discovered in ProjectSend before r1053.projectsend · projectsend · CWE-79 | Orta6,1 | — | %0,8 | 22 May 2019 |
24İzleyin | CVE-2023-53905İstismar yok | ProjectSend r1605 CSV Injection via User Account Export Functionalityprojectsend · projectsend · CWE-1236 | Orta6,2 | — | %0,5 | 17 Ara 2025 |
22İzleyin | CVE-2017-20101İstismar yok | ProjectSend information disclosureprojectsend · projectsend · CWE-200 | Orta5,7 | — | %1,1 | 27 Haz 2022 |
- CVE-2024-1168097Hemen
ProjectSend Unauthenticated Configuration Modification
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92projectsend · projectsend26 Kas 2024
- CVE-2014-956743Planlayın
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to exe
YüksekCVSS 7,5SilahlaştırılmışEPSS %43projectsend · projectsend7 Oca 2015
- CVE-2021-4088740Planlayın
Projectsend version r1295 is affected by a directory traversal vulnerability.
KritikCVSS 9,8İstismar yokEPSS %2projectsend · projectsend11 Eki 2021
- CVE-2016-1073340Planlayın
ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
KritikCVSS 9,8İstismar yokEPSS %2projectsend · projectsend29 Eki 2018
- CVE-2016-1073240Planlayın
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or proc
KritikCVSS 9,8İstismar yokEPSS %2projectsend · projectsend29 Eki 2018
- CVE-2017-974139İzleyin
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to rep
KritikCVSS 9,8İstismar yokEPSS %2projectsend · projectsend18 Haz 2017
- CVE-2016-1073439İzleyin
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
KritikCVSS 9,8İstismar yokEPSS %2projectsend · projectsend29 Eki 2018
- CVE-2016-1073139İzleyin
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the requ
KritikCVSS 9,8İstismar yokEPSS %1projectsend · projectsend29 Eki 2018
- CVE-2019-1137836İzleyin
An issue was discovered in ProjectSend r1053.
YüksekCVSS 8,8İstismar yokEPSS %4projectsend · projectsend20 Nis 2019
- CVE-2018-720135İzleyin
CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.
YüksekCVSS 8,8İstismar yokEPSS %1projectsend · projectsend22 May 2019
- CVE-2023-5398034İzleyin
ProjectSend r1605 Remote Code Execution via File Extension Manipulation
YüksekCVSS 8,7İstismar yokEPSS %1projectsend · projectsend22 Ara 2025
- CVE-2021-4088432İzleyin
Projectsend version r1295 is affected by sensitive information disclosure.
YüksekCVSS 8,1İstismar yokEPSS %1projectsend · projectsend11 Eki 2021
- CVE-2020-2887431İzleyin
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic.
YüksekCVSS 7,5Kavram kanıtıEPSS %2projectsend · projectsend26 Oca 2021
- CVE-2019-1149230İzleyin
ProjectSend before r1070 writes user passwords to the server logs.
YüksekCVSS 7,5İstismar yokEPSS %1projectsend · projectsend26 Nis 2019
- CVE-2023-5393028İzleyin
ProjectSend r1605 Insecure Direct Object Reference File Download Vulnerability
YüksekCVSS 7,1İstismar yokEPSS %0projectsend · projectsend17 Ara 2025
- CVE-2015-256427İzleyin
SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQ
OrtaCVSS 6,5Kavram kanıtıEPSS %3projectsend · projectsend20 Mar 2015
- CVE-2024-765827İzleyin
projectsend process.php get_preview resource injection
OrtaCVSS 6,9İstismar yokEPSS %1projectsend · projectsend12 Ağu 2024
- CVE-2021-4088626İzleyin
Projectsend version r1295 is affected by a directory traversal vulnerability.
OrtaCVSS 6,5İstismar yokEPSS %1projectsend · projectsend11 Eki 2021
- CVE-2024-765925İzleyin
projectsend Password Reset Token functions.php generate_random_string random values
OrtaCVSS 6,3İstismar yokEPSS %1projectsend · projectsend12 Ağu 2024
- CVE-2019-1153324İzleyin
Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web script or HTML.
OrtaCVSS 6,1İstismar yokEPSS %1projectsend · projectsend26 Nis 2019
- CVE-2017-978324İzleyin
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote
OrtaCVSS 6,1İstismar yokEPSS %1projectsend · projectsend6 Mar 2018
- CVE-2017-978624İzleyin
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote
OrtaCVSS 6,1İstismar yokEPSS %1projectsend · projectsend6 Mar 2018
- CVE-2018-720224İzleyin
An issue was discovered in ProjectSend before r1053.
OrtaCVSS 6,1İstismar yokEPSS %1projectsend · projectsend22 May 2019
- CVE-2023-5390524İzleyin
ProjectSend r1605 CSV Injection via User Account Export Functionality
OrtaCVSS 6,2İstismar yokEPSS %1projectsend · projectsend17 Ara 2025
- CVE-2017-2010122İzleyin
ProjectSend information disclosure
OrtaCVSS 5,7İstismar yokEPSS %1projectsend · projectsend27 Haz 2022