Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dotproject MEDIUM 6.8
CVE-2012-5701

Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commands via the…

Fix: after 2.1.6
Fix from $1,600 2014-10-20
Dotproject MEDIUM 5.0
CVE-2011-3729

dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in …

No fix yet
Fix from $1,600 2011-09-23
Dotproject MEDIUM 6.8
CVE-2008-6747

dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of t…

Fix: after 2.1.1
Fix from $1,600 2009-04-23
Dotproject MEDIUM 6.0
CVE-2008-3887

Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via th…

No fix yet
Fix from $1,600 2008-09-02
Dotproject MEDIUM 6.4
CVE-2007-5486

dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via …

Fix: after 2.0.4
Fix from $1,600 2007-10-16
Dotproject HIGH 7.5
CVE-2006-4234EPSS 6%

PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP c…

No fix yet
Fix from $1,950 2006-08-18
Dotproject MEDIUM 5.6
CVE-2006-0755EPSS 8%

Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute…

No fix yet
Fix from $1,600 2006-02-18
Dotproject MEDIUM 5.0
CVE-2006-0754

dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain PHP scrip…

No fix yet
Fix from $1,600 2006-02-18
Dotproject MEDIUM 5.0
CVE-2006-0756

dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote a…

No fix yet
Fix from $1,600 2006-02-18
Dotproject HIGH 10.0
CVE-2002-1428EPSS 6%

index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.

No fix yet
Fix from $1,950 2003-04-11