Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Flyspray MEDIUM 5.4
CVE-2017-15213

Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via the real_…

Fix: after 1.0
Fix from $1,600 2017-10-11
Flyspray MEDIUM 5.4
CVE-2017-15214

Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges and al…

Patch available
Fix from $1,600 2017-10-11
Flyspray MEDIUM 6.0
CVE-2012-1058

Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requests that …

No fix yet
Fix from $1,600 2012-02-14
Flyspray MEDIUM 5.0
CVE-2008-1166

Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate…

Mitigation only
Fix from $1,600 2008-03-05
Flyspray MEDIUM 6.8
CVE-2007-1788

Flyspray 0.9.9, when output_buffering is disabled or "set to a low value," allows remote attackers to bypass authentication via a crafted post reques…

Mitigation only
Fix from $1,600 2007-03-31
Flyspray MEDIUM 6.8
CVE-2007-1789

Flyspray 0.9.9 allows remote attackers to obtain sensitive information (private project summaries) via direct requests.

Mitigation only
Fix from $1,600 2007-03-31
Flyspray MEDIUM 5.0
CVE-2006-0714EPSS 8%

Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary fil…

Patch available
Fix from $1,600 2006-02-15