Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phprojekt MEDIUM 5.0
CVE-2011-3786

PHProjekt 6.0.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in a…

Mitigation only
Fix from $1,600 2011-09-24
Phprojekt HIGH 7.5
CVE-2007-1575

Multiple SQL injection vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary S…

Patch available
Fix from $1,950 2007-03-21
Phprojekt HIGH 7.5
CVE-2006-5123

Multiple PHP remote file inclusion vulnerabilities in Albrecht Guenther PHProjekt 5.1.x before 5.1.2 allow remote attackers to execute arbitrary PHP …

Fix: after 5.1.1
Fix from $1,950 2006-10-03
Phprojekt HIGH 7.5
CVE-2006-4204EPSS 8%

Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP code via a U…

Fix: after 5.1
Fix from $1,950 2006-08-17
Phprojekt MEDIUM 5.1
CVE-2005-1227

Cross-site scripting (XSS) vulnerability in PHProjekt 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the chatroom…

No fix yet
Fix from $1,600 2005-04-20
Phprojekt HIGH 7.5
CVE-2004-2739

The setup routine (setup.php) in PHProjekt 4.2.1 and earlier allows remote attackers to modify system configuration via unknown attack vectors.

Patch available
Fix from $1,950 2004-12-31
Phprojekt HIGH 7.5
CVE-2002-1757

PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via…

Patch available
Fix from $1,950 2002-12-31
Phprojekt HIGH 7.5
CVE-2002-1760

Multiple SQL injection vulnerabilities in PHProjekt 2.0 through 3.1 allow remote attackers to execute arbitrary SQL commands via the unknown attack v…

Patch available
Fix from $1,950 2002-12-31
Phprojekt MEDIUM 5.0
CVE-2002-1758

PHProjekt 2.0 through 3.1 allows remote attackers to view or modify data via requests to certain scripts that do not verify if the user is logged in.

Patch available
Fix from $1,600 2002-12-31
Phprojekt MEDIUM 5.0
CVE-2002-1759

The upload function in PHProjekt 2.0 through 3.1 does not properly verify certain variables related to uploaded data, which allows remote attackers t…

Patch available
Fix from $1,600 2002-12-31
Phprojekt MEDIUM 5.0
CVE-2002-1761

Directory traversal vulnerability in PHProjekt 2.0 through 3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences.

Mitigation only
Fix from $1,600 2002-12-31
Phprojekt MEDIUM 5.0
CVE-2001-0648

Directory traversal vulnerability in PHProjekt 2.1 and earlier allows a remote attacker to conduct unauthorized activities via a dot dot (..) attack …

Patch available
Fix from $1,600 2001-09-20