CVE-2006-2851
- EPSS 0.62%
- Veröffentlicht 06.06.2006 20:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in index.php in dotProject 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, which are not properly handled when the client is using Internet Explorer...
- EPSS 0.7%
- Veröffentlicht 18.02.2006 02:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain PHP scripts in the db directory, which reveal the path in an error message. NOTE: the vendor disputes this is...
CVE-2006-0755
- EPSS 11.23%
- Veröffentlicht 18.02.2006 02:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.ph...
- EPSS 1.02%
- Veröffentlicht 18.02.2006 02:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote attackers to obtain sensitive configuration information. NOTE: the vendor disputes this issue, saying...
- EPSS 5.31%
- Veröffentlicht 11.04.2003 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.