Show filters
89 Total Results
Displaying 81-89 of 89
Sort by:
Attacker Value
Unknown
CVE-2006-3240
Disclosure Date: June 27, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in classes/ui.class.php in dotProject 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter.
0
Attacker Value
Unknown
CVE-2006-3189
Disclosure Date: June 23, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
0
Attacker Value
Unknown
CVE-2006-3190
Disclosure Date: June 23, 2006 (last updated October 04, 2023)
SQL injection vulnerability in administration/includes/login/auth.php in HotPlug CMS 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.
0
Attacker Value
Unknown
CVE-2006-2851
Disclosure Date: June 06, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in dotProject 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, which are not properly handled when the client is using Internet Explorer.
0
Attacker Value
Unknown
CVE-2006-0755
Disclosure Date: February 18, 2006 (last updated February 22, 2025)
Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.php, (4) vw_usr_roles.php, (5) calendar.php, (6) date_format.php, and (7) tasks/gantt.php; and the dPconfig[root_dir] parameter in (8) projects/gantt.php, (9) gantt2.php, and (10) vw_files.php. NOTE: the vendor disputes this issue, stating that the product documentation clearly recommends that the system administrator disable register_globals, and that the check.php script warns against this setting. Also, the vendor says that the protection.php/siteurl vector is incorrect because protection.php does not exist in the product
0
Attacker Value
Unknown
CVE-2006-0754
Disclosure Date: February 18, 2006 (last updated February 22, 2025)
dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain PHP scripts in the db directory, which reveal the path in an error message. NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php
0
Attacker Value
Unknown
CVE-2006-0756
Disclosure Date: February 18, 2006 (last updated February 22, 2025)
dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote attackers to obtain sensitive configuration information. NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php
0
Attacker Value
Unknown
CVE-2002-1428
Disclosure Date: April 11, 2003 (last updated February 22, 2025)
index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.
0
Attacker Value
Unknown
CVE-1999-0799
Disclosure Date: June 01, 1997 (last updated February 22, 2025)
Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.
0