Show filters
89 Total Results
Displaying 71-80 of 89
Sort by:
Attacker Value
Unknown

CVE-2008-3886

Disclosure Date: September 02, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the inactive parameter in a tasks action, (2) the date parameter in a calendar day_view action, (3) the callback parameter in a public calendar action, or (4) the type parameter in a ticketsmith action.
0
Attacker Value
Unknown

CVE-2008-3887

Disclosure Date: September 02, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the tab parameter in a projects action, and (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in a viewuser action.
0
Attacker Value
Unknown

CVE-2008-1214

Disclosure Date: March 08, 2008 (last updated October 04, 2023)
MRcgi/MRProcessIncomingForms.pl in Numara FootPrints 8.1 on Linux allows remote attackers to execute arbitrary code via shell metacharacters in the PROJECTNUM parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-1213

Disclosure Date: March 08, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Numara FootPrints for Linux 8.1 allows remote attackers to inject arbitrary web script or HTML via the Title form field when setting an appointment. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-6030

Disclosure Date: November 20, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Weird Solutions BOOTPTurbo 1.2 has unknown impact and remote attack vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.
0
Attacker Value
Unknown

CVE-2007-5486

Disclosure Date: October 16, 2007 (last updated October 04, 2023)
dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via a crafted URL. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-3226

Disclosure Date: June 14, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in dotProject before 2.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2006-2851 and CVE-2006-3240.
0
Attacker Value
Unknown

CVE-2006-5041

Disclosure Date: September 27, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Hot Properties (possibly com_hotproperties) 0.97 and earlier for Joomla! has unspecified impact and attack vectors.
0
Attacker Value
Unknown

CVE-2006-4772

Disclosure Date: September 14, 2006 (last updated October 04, 2023)
HotPlug CMS stores sensitive information under the web root with insufficient access control, which allows remote attackers to read the admin password and database credentials via a direct request for includes/class/config.inc.
0
Attacker Value
Unknown

CVE-2006-4234

Disclosure Date: August 18, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.
0