dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of these details are obtained from third party information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dotproject | Dotproject | * | 2.1.1 (including) |
Dotproject | Dotproject | 0.2.1.5 (including) | 0.2.1.5 (including) |
Dotproject | Dotproject | 2.0 (including) | 2.0 (including) |
Dotproject | Dotproject | 2.0.1 (including) | 2.0.1 (including) |
Dotproject | Dotproject | 2.0.2 (including) | 2.0.2 (including) |
Dotproject | Dotproject | 2.0.3 (including) | 2.0.3 (including) |
Dotproject | Dotproject | 2.0.4 (including) | 2.0.4 (including) |
Dotproject | Dotproject | 2.1 (including) | 2.1 (including) |
Dotproject | Dotproject | 2.1-rc2 (including) | 2.1-rc2 (including) |
Dotproject | Dotproject | 2.1.0-rc1 (including) | 2.1.0-rc1 (including) |