Show filters
501 Total Results
Displaying 391-400 of 501
Sort by:
Attacker Value
Unknown
CVE-2011-3797
Disclosure Date: September 24, 2011 (last updated October 04, 2023)
ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files.
0
Attacker Value
Unknown
CVE-2011-3729
Disclosure Date: September 23, 2011 (last updated October 04, 2023)
dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by style/dp-grey-theme/footer.php and certain other files.
0
Attacker Value
Unknown
CVE-2011-1911
Disclosure Date: September 20, 2011 (last updated October 04, 2023)
JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach.
0
Attacker Value
Unknown
CVE-2011-2697
Disclosure Date: July 29, 2011 (last updated October 04, 2023)
foomatic-rip-hplip in HP Linux Imaging and Printing (HPLIP) 3.11.5 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file.
0
Attacker Value
Unknown
CVE-2010-4267
Disclosure Date: January 20, 2011 (last updated October 04, 2023)
Stack-based buffer overflow in the hpmud_get_pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP) 1.6.7, 3.9.8, 3.10.9, and probably other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SNMP response with a large length value.
0
Attacker Value
Unknown
CVE-2010-2134
Disclosure Date: June 02, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in login.php in Project Man 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.
0
Attacker Value
Unknown
CVE-2010-1469
Disclosure Date: April 19, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the Ternaria Informatica JProject Manager (com_jprojectmanager) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown
CVE-2010-1363
Disclosure Date: April 13, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the JProjects (com_j-projects) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the project parameter in a projects action to index.php.
0
Attacker Value
Unknown
CVE-2010-0452
Disclosure Date: March 29, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in HP Project and Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1 through SP10 and 7.5 through SP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-0102
Disclosure Date: December 09, 2009 (last updated October 04, 2023)
Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."
0