Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2012-5701 Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commands via the… Dotproject after 2.1.6 Fix from $1,6002014-10-20 MEDIUM 5.0 CVE-2011-3729 dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in … Dotproject No fix yet Fix from $1,6002011-09-23 MEDIUM 6.8 CVE-2008-6747 dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of t… Dotproject after 2.1.1 Fix from $1,6002009-04-23 MEDIUM 6.0 CVE-2008-3887 Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via th… Dotproject No fix yet Fix from $1,6002008-09-02 MEDIUM 6.4 CVE-2007-5486 dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via … Dotproject after 2.0.4 Fix from $1,6002007-10-16 HIGH 7.5 CVE-2006-4234EPSS 6% PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP c… Dotproject No fix yet Fix from $1,9502006-08-18 MEDIUM 5.6 CVE-2006-0755EPSS 8% Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute… Dotproject No fix yet Fix from $1,6002006-02-18 MEDIUM 5.0 CVE-2006-0754 dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain PHP scrip… Dotproject No fix yet Fix from $1,6002006-02-18 MEDIUM 5.0 CVE-2006-0756 dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote a… Dotproject No fix yet Fix from $1,6002006-02-18 HIGH 10.0 CVE-2002-1428EPSS 6% index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1. Dotproject No fix yet Fix from $1,9502003-04-11