Dotproject Multiple SQL Injection and Cross Site Scripting Vulnerabilities
BID:56624
Info
Dotproject Multiple SQL Injection and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 56624 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5701 CVE-2012-5702 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 21 2012 12:00AM |
| Updated: | Mar 19 2015 08:16AM |
| Credit: | High-Tech Bridge Security Research Lab |
| Vulnerable: |
Dotproject Dotproject 2.1.6 Dotproject Dotproject 2.1.5 Dotproject Dotproject 2.1.3 Dotproject Dotproject 2.1.2 Dotproject Dotproject 2.1.1 Dotproject Dotproject 2.1-Rc2 Dotproject Dotproject 2.1 |
| Not Vulnerable: |
Dotproject Dotproject 2.1.7 |
Solution / Fix
Dotproject Multiple SQL Injection and Cross Site Scripting Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Dotproject Multiple SQL Injection and Cross Site Scripting Vulnerabilities
References:
References:
- dotProject Web Site (dotProject)