Multiple cross-site scripting (XSS) vulnerabilities in Outreach Project Tool (OPT) 0.946b allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the news field.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lanifex | outreach_project_tool | 0.946b |
PHP remote file inclusion vulnerability in LFXlib/access_manager.php in Lanifex Database of Managed Objects (DMO) 2.3 Beta and earlier allows remote attackers to execute arbitrary PHP code via the _incMgr parameter.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lanifex | lanifex | 2.2 |
| lanifex | lanifex | * |
PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CRM_path parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| lanifex | outreach_project_tool | 0.947 |
| lanifex | outreach_project_tool | 0.942 |
| lanifex | outreach_project_tool | 0.946 |
| lanifex | outreach_project_tool | 0.934 |
| lanifex | outreach_project_tool | 0.943 |
| lanifex | outreach_project_tool | 0.945 |
| lanifex | outreach_project_tool | 0.941 |
| lanifex | outreach_project_tool | 0.933 |
| lanifex | outreach_project_tool | 0.937 |
| lanifex | outreach_project_tool | 0.94 |
| lanifex | outreach_project_tool | 0.936 |
| lanifex | outreach_project_tool | 0.944 |
| lanifex | outreach_project_tool | 0.939 |
| lanifex | outreach_project_tool | 1.2.6 |
| lanifex | outreach_project_tool | * |
| lanifex | outreach_project_tool | 0.935 |
| lanifex | outreach_project_tool | 0.938 |
| lanifex | outreach_project_tool | 0.948 |