Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
projectpier projectpier vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-5583
Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and previous versions allows remote malicious users to perform actions as an administrator via the query string, as demonstrated by a delete project action.
Projectpier Projectpier
NA
CVE-2008-5584
Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and previous versions allow remote malicious users to inject arbitrary web script or HTML via (1) a message, (2) a milestone, or (3) a display name in a profile, or the (4) a or (5) c parameter to index.php.
Projectpier Projectpier
1 EDB exploit
9.8
CVSSv3
CVE-2018-10759
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and previous versions allows remote malicious users to execute arbitrary commands or SQL statements via the id parameter.
Projectpier Projectpier
8.8
CVSSv3
CVE-2018-10760
Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and previous versions allows remote authenticated users to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the tmp dir...
Projectpier Projectpier
5.4
CVSSv3
CVE-2013-3637
ProjectPier 0.8.8 does not use the Secure flag for cookies
Projectpier Projectpier 0.8.8
5.4
CVSSv3
CVE-2013-3636
ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag
Projectpier Projectpier 0.8.8
5.4
CVSSv3
CVE-2013-3635
ProjectPier 0.8.8 has stored XSS
Projectpier Projectpier 0.8.8
6.1
CVSSv3
CVE-2015-2796
Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote malicious users to inject arbitrary web script or HTML via the search_for parameter to (1) search_by_tag.php, (2) search_contacts.php, or (3) search.php.
Projectpier Projectpier 0.8.8
NA
CVE-2011-3797
ProjectPier 0.8.0.3 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files.
Projectpier Projectpier 0.8.0.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3080
log injection
CVE-2024-6041
CVE-2024-37661
XML external entity
CVE-2024-0845
privilege escalation
CVE-2023-37057
CVE-2024-27801
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started