Qdpm

Qdpm

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.94%
  • Veröffentlicht 16.04.2020 19:15:27
  • Zuletzt bearbeitet 21.11.2024 04:58:40

In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type value. After that, the attacker can execute an arbitrary command on the server using this malicious fil...

Exploit
  • EPSS 90.59%
  • Veröffentlicht 21.01.2020 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:36:54

A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo...

Exploit
  • EPSS 1.29%
  • Veröffentlicht 14.05.2019 16:29:02
  • Zuletzt bearbeitet 21.11.2024 04:49:49

qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.

Exploit
  • EPSS 2.61%
  • Veröffentlicht 14.05.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:49:49

qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 17.03.2017 14:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/databases.yml, (2) core/log/qdPM_prod.log, or (3) core/apps/qdPM/config/settings.yml.

Exploit
  • EPSS 72.92%
  • Veröffentlicht 17.03.2017 14:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pages in qdPM 8.3 allows remote attackers to execute arbitrary code by uploading a file with an executa...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 17.03.2017 14:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) search[keywords] parameter to index.php/users page; the (2) "Name of application" on index.php/configuration; (3...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 17.03.2017 14:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the installation path in an error message.