6.8
CVSSv2

CVE-2012-5701

Published: 20/10/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in dotProject prior to 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search_string or (2) where parameter in a contacts action, (3) dept_id parameter in a departments action, (4) project_id[] parameter in a project action, or (5) company_id parameter in a system action to index.php. NOTE: this can be leveraged using CSRF to allow remote malicious users to execute arbitrary SQL commands.

Vulnerable Product Search on Vulmon Subscribe to Product

dotproject dotproject

Exploits

source: wwwsecurityfocuscom/bid/56624/info Dotproject is prone to the following security vulnerabilities: 1 Multiple SQL-injection vulnerabilities 2 Multiple cross-site scripting vulnerabilities Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, acces ...
dotProject version 216 suffers from cross site scripting and remote SQL injection vulnerabilities ...