qdPM

qdPM is a free web-based project management tool suitable for a small team working on multiple projects. It is fully configurable. You can easy manage Projects Tasks and People. Customers interact using a Ticket System that is integrated into Task management.

Official Site:

http://qdpm.net/

Severity Summary:

Critical: 3 High: 5 Medium: 8
Reference
Title
Severity
qdPM Unrestricted Upload of File with Dangerous Type Vulnerability
Critical
qdPM Code Execution Vulnerability
Critical
qdPM Unrestricted Upload of File with Dangerous Type Vulnerability
Critical
qdPM Sensitive Information Disclosure Vulnerability
High
qdPM Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
High
qdPM Improper Control of Generation of Code (Code Injection) Vulnerability
High
qdPM Cross-Site Request Forgery (CSRF) Vulnerability
High
qdPM Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
High
qdPM Sensitive Information Disclosure Vulnerability
Medium
qdPM Multiple Cross-site Scripting (XSS) Vulnerabilities
Medium
qdPM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
qdPM Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
Medium
qdPM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
qdPM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
qdPM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
qdPM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium