Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2012-5702

Disclosure Date: October 21, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to index.php. NOTE: the date parameter vector is already covered by CVE-2008-3886.
0
Attacker Value
Unknown

CVE-2012-5701

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search_string or (2) where parameter in a contacts action, (3) dept_id parameter in a departments action, (4) project_id[] parameter in a project action, or (5) company_id parameter in a system action to index.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.
0
Attacker Value
Unknown

CVE-2011-3729

Disclosure Date: September 23, 2011 (last updated October 04, 2023)
dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by style/dp-grey-theme/footer.php and certain other files.
0
Attacker Value
Unknown

CVE-2008-6747

Disclosure Date: April 23, 2009 (last updated October 04, 2023)
dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-3886

Disclosure Date: September 02, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the inactive parameter in a tasks action, (2) the date parameter in a calendar day_view action, (3) the callback parameter in a public calendar action, or (4) the type parameter in a ticketsmith action.
0
Attacker Value
Unknown

CVE-2008-3887

Disclosure Date: September 02, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the tab parameter in a projects action, and (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in a viewuser action.
0
Attacker Value
Unknown

CVE-2007-5486

Disclosure Date: October 16, 2007 (last updated October 04, 2023)
dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via a crafted URL. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-3226

Disclosure Date: June 14, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in dotProject before 2.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2006-2851 and CVE-2006-3240.
0
Attacker Value
Unknown

CVE-2006-4234

Disclosure Date: August 18, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.
0
Attacker Value
Unknown

CVE-2006-3240

Disclosure Date: June 27, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in classes/ui.class.php in dotProject 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter.
0