Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181.
Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (cr…
Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.
In Inedo BuildMaster before 5.8.2, XslTransform was used where XslCompiledTransform should have been used.
Inedo BuildMaster before 5.8.2 has XSS.
An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites.
Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060.