Show filters
501 Total Results
Displaying 391-400 of 501
Sort by:
Attacker Value
Unknown

CVE-2011-3797

Disclosure Date: September 24, 2011 (last updated October 04, 2023)
ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files.
0
Attacker Value
Unknown

CVE-2011-3729

Disclosure Date: September 23, 2011 (last updated October 04, 2023)
dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by style/dp-grey-theme/footer.php and certain other files.
0
Attacker Value
Unknown

CVE-2011-1911

Disclosure Date: September 20, 2011 (last updated October 04, 2023)
JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach.
0
Attacker Value
Unknown

CVE-2011-2697

Disclosure Date: July 29, 2011 (last updated October 04, 2023)
foomatic-rip-hplip in HP Linux Imaging and Printing (HPLIP) 3.11.5 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file.
0
Attacker Value
Unknown

CVE-2010-4267

Disclosure Date: January 20, 2011 (last updated October 04, 2023)
Stack-based buffer overflow in the hpmud_get_pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP) 1.6.7, 3.9.8, 3.10.9, and probably other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SNMP response with a large length value.
0
Attacker Value
Unknown

CVE-2010-2134

Disclosure Date: June 02, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in login.php in Project Man 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.
0
Attacker Value
Unknown

CVE-2010-1469

Disclosure Date: April 19, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the Ternaria Informatica JProject Manager (com_jprojectmanager) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown

CVE-2010-1363

Disclosure Date: April 13, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the JProjects (com_j-projects) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the project parameter in a projects action to index.php.
0
Attacker Value
Unknown

CVE-2010-0452

Disclosure Date: March 29, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in HP Project and Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1 through SP10 and 7.5 through SP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-0102

Disclosure Date: December 09, 2009 (last updated October 04, 2023)
Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."
0