Qdpm kayıtları
qdpm üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %11,1
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2020-7246Silahlaştırılmış | A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier.qdpm · qdpm · CWE-22 | Yüksek8,8 | — | %83,2 | 21 Oca 2020 |
40Planlayın | CVE-2020-11811İstismar yok | In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted contenqdpm · qdpm · CWE-434 | Kritik9,8 | — | %3,0 | 16 Nis 2020 |
39İzleyin | CVE-2015-3884Silahlaştırılmış | Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) schqdpm · qdpm · CWE-434 | Yüksek8,8 | — | %14,4 | 17 Mar 2017 |
39İzleyin | CVE-2023-45856İstismar yok | qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.qdpm · qdpm · CWE-434 | Kritik9,8 | — | %1,4 | 14 Eki 2023 |
36İzleyin | CVE-2022-26180Kavram kanıtı | qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.qdpm · qdpm · CWE-352 | Yüksek8,8 | — | %3,8 | 8 Nis 2022 |
36İzleyin | CVE-2020-26165İstismar yok | qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.classqdpm · qdpm · CWE-502 | Yüksek8,8 | — | %2,5 | 31 Ara 2020 |
35İzleyin | CVE-2018-25208İstismar yok | qdPM 9.1 SQL Injection via filter_by Parametersqdpm · qdpm · CWE-89 | Yüksek8,8 | — | %0,3 | 26 Mar 2026 |
35İzleyin | CVE-2019-25669İstismar yok | qdPM 9.1 SQL Injection via search_by_extrafields Parameterqdpm · qdpm · CWE-89 | Yüksek8,8 | — | %0,3 | 5 Nis 2026 |
31İzleyin | CVE-2023-45855Kavram kanıtı | qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.qdpm · qdpm · CWE-22 | Yüksek7,5 | — | %3,3 | 14 Eki 2023 |
30İzleyin | CVE-2015-3881İstismar yok | Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/datqdpm · qdpm · CWE-200 | Yüksek7,5 | — | %1,5 | 17 Mar 2017 |
27İzleyin | CVE-2019-8390Kavram kanıtı | qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.qdpm · qdpm · CWE-79 | Orta6,1 | — | %9,8 | 14 May 2019 |
25İzleyin | CVE-2019-8391Kavram kanıtı | qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.qdpm · qdpm · CWE-79 | Orta6,1 | — | %3,3 | 14 May 2019 |
25İzleyin | CVE-2020-19515Kavram kanıtı | qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.qdpm · qdpm · CWE-79 | Orta6,1 | — | %1,8 | 9 Eyl 2021 |
24İzleyin | CVE-2015-3883İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) seqdpm · qdpm · CWE-79 | Orta6,1 | — | %0,8 | 17 Mar 2017 |
21İzleyin | CVE-2015-3882İstismar yok | qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the insqdpm · qdpm · CWE-200 | Orta5,3 | — | %1,2 | 17 Mar 2017 |
21İzleyin | CVE-2020-11814İstismar yok | A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious websiteqdpm · qdpm · CWE-74 | Orta5,4 | — | %1,0 | 16 Nis 2020 |
21İzleyin | CVE-2020-26166İstismar yok | The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web scriqdpm · qdpm · CWE-79 | Orta5,4 | — | %0,8 | 5 Eki 2020 |
21İzleyin | CVE-2020-18468İstismar yok | Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a cqdpm · qdpm · CWE-79 | Orta5,4 | — | %0,4 | 26 Ağu 2021 |
- CVE-2020-724660Bu hafta
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier.
YüksekCVSS 8,8SilahlaştırılmışEPSS %83qdpm · qdpm21 Oca 2020
- CVE-2020-1181140Planlayın
In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted conten
KritikCVSS 9,8İstismar yokEPSS %3qdpm · qdpm16 Nis 2020
- CVE-2015-388439İzleyin
Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) sch
YüksekCVSS 8,8SilahlaştırılmışEPSS %14qdpm · qdpm17 Mar 2017
- CVE-2023-4585639İzleyin
qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.
KritikCVSS 9,8İstismar yokEPSS %1qdpm · qdpm14 Eki 2023
- CVE-2022-2618036İzleyin
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
YüksekCVSS 8,8Kavram kanıtıEPSS %4qdpm · qdpm8 Nis 2022
- CVE-2020-2616536İzleyin
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class
YüksekCVSS 8,8İstismar yokEPSS %3qdpm · qdpm31 Ara 2020
- CVE-2018-2520835İzleyin
qdPM 9.1 SQL Injection via filter_by Parameters
YüksekCVSS 8,8İstismar yokEPSS %0qdpm · qdpm26 Mar 2026
- CVE-2019-2566935İzleyin
qdPM 9.1 SQL Injection via search_by_extrafields Parameter
YüksekCVSS 8,8İstismar yokEPSS %0qdpm · qdpm5 Nis 2026
- CVE-2023-4585531İzleyin
qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.
YüksekCVSS 7,5Kavram kanıtıEPSS %3qdpm · qdpm14 Eki 2023
- CVE-2015-388130İzleyin
Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/dat
YüksekCVSS 7,5İstismar yokEPSS %2qdpm · qdpm17 Mar 2017
- CVE-2019-839027İzleyin
qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %10qdpm · qdpm14 May 2019
- CVE-2019-839125İzleyin
qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %3qdpm · qdpm14 May 2019
- CVE-2020-1951525İzleyin
qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
OrtaCVSS 6,1Kavram kanıtıEPSS %2qdpm · qdpm9 Eyl 2021
- CVE-2015-388324İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) se
OrtaCVSS 6,1İstismar yokEPSS %1qdpm · qdpm17 Mar 2017
- CVE-2015-388221İzleyin
qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the ins
OrtaCVSS 5,3İstismar yokEPSS %1qdpm · qdpm17 Mar 2017
- CVE-2020-1181421İzleyin
A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious website
OrtaCVSS 5,4İstismar yokEPSS %1qdpm · qdpm16 Nis 2020
- CVE-2020-2616621İzleyin
The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web scri
OrtaCVSS 5,4İstismar yokEPSS %1qdpm · qdpm5 Eki 2020
- CVE-2020-1846821İzleyin
Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a c
OrtaCVSS 5,4İstismar yokEPSS %0qdpm · qdpm26 Ağu 2021