Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2017-15213
Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via the real_…
Flyspray
after 1.0
MEDIUM 5.4
CVE-2017-15214
Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges and al…
Flyspray
Patch available
MEDIUM 6.0
CVE-2012-1058
Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requests that …
Flyspray
No fix yet
MEDIUM 5.0
CVE-2008-1166
Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate…
Flyspray
Mitigation only
MEDIUM 6.8
CVE-2007-1788
Flyspray 0.9.9, when output_buffering is disabled or "set to a low value," allows remote attackers to bypass authentication via a crafted post reques…
Flyspray
Mitigation only
MEDIUM 6.8
CVE-2007-1789
Flyspray 0.9.9 allows remote attackers to obtain sensitive information (private project summaries) via direct requests.
Flyspray
Mitigation only
MEDIUM 5.0
CVE-2006-0714EPSS 8%
Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary fil…
Flyspray
Patch available