ProjectSend

ProjectSend (previously cFTP) is a clients-oriented file uploading utility. Clients are created and assigned a username and a password. Then you can upload as much files as you want under each account with the ability to add a title and description to each one. ProjectSend provides easy and secure multi-file uploading and unlimited file size on ANY server Even on common hostings shared accounts.

Severity Summary:

Critical: 3 High: 6 Medium: 9
Reference
Title
Severity
ProjectSend Incorrect Authorization Vulnerability
Critical
ProjectSend Improper Input Validation Vulnerability
Critical
ProjectSend Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Critical
ProjectSend Improper Neutralization of Formula Elements in a CSV File Vulnerability
High
ProjectSend Use of Insufficiently Random Values Vulnerability
High
ProjectSend Improper Privilege Management Vulnerability
High
ProjectSend Insertion of Sensitive Information into Log File Vulnerability
High
ProjectSend Incorrect Authorization Vulnerability
High
ProjectSend Unrestricted Upload of File with Dangerous Type Vulnerability
High
ProjectSend Authorization Bypass Through User-Controlled Key Vulnerability
Medium
ProjectSend Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
ProjectSend Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
ProjectSend Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
ProjectSend Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
ProjectSend Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Medium
ProjectSend Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
ProjectSend Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
ProjectSend Authorization Bypass Through User-Controlled Key Vulnerability
Medium