Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
qdpm vulnerabilities and exploits
(subscribe to this query)
656
VMScore
CVE-2020-7246
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and previous versions. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature, ...
Qdpm Qdpm
1 EDB exploit
4 Github repositories
578
VMScore
CVE-2020-26165
qdPM up to and including 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.
Qdpm Qdpm
690
VMScore
CVE-2015-3884
Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pages in qdPM 8.3 allows remote malicious users to execute arbitrary code by uploading a file with an executable extension, then acce...
Qdpm Qdpm
1 Metasploit module
1 Github repository
445
VMScore
CVE-2015-3881
Information disclosure issue in qdPM 8.3 allows remote malicious users to obtain sensitive information via a direct request to (1) core/config/databases.yml, (2) core/log/qdPM_prod.log, or (3) core/apps/qdPM/config/settings.yml.
Qdpm Qdpm 8.3
383
VMScore
CVE-2019-8390
qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
Qdpm Qdpm 9.1
383
VMScore
CVE-2019-8391
qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.
Qdpm Qdpm 9.1
890
VMScore
CVE-2020-11811
In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type value. After that, the attacker can execute an arbitrary command on the server using this malicious file.
Qdpm Qdpm 9.1
312
VMScore
CVE-2020-26166
The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated malicious users to inject web script or HTML via the attachments info parameter, aka XSS. This can occur during creation of a ticket, project, or task.
Qdpm Qdpm 9.1
516
VMScore
CVE-2020-11814
A Host Header Injection vulnerability in qdPM 9.1 may allow an malicious user to spoof a particular header and redirect users to malicious websites.
Qdpm Qdpm 9.1
605
VMScore
CVE-2022-26180
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
Qdpm Qdpm 9.2
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »