CVE-2024-38189 – Microsoft Project Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-38189
Microsoft Project Remote Code Execution Vulnerability Microsoft Project contains an unspecified vulnerability that allows for remote code execution via a malicious file. • https://github.com/vx7z/CVE-2024-38189 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38189 • CWE-20: Improper Input Validation •
CVE-2021-4225 – SP Project & Document Manager < 4.24 - Subscriber+ Shell Upload
https://notcve.org/view.php?id=CVE-2021-4225
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows servers, the security checks in place were insufficient, enabling bad actors to potentially upload backdoors on vulnerable sites. El plugin SP Project & Document Manager de WordPress versiones anteriores a 4.24, permite a cualquier usuario autenticado, como los suscriptores, subir archivos. El plugin intenta evitar que sean subidos archivos PHP y otros similares que podrían ejecutarse en el servidor, comprobando la extensión del archivo. • https://github.com/pang0lin/CVEproject/blob/main/wordpress_SP-Project_fileupload.md https://wpscan.com/vulnerability/bd1083d1-edcc-482e-a8a9-c8b6c8d417bd • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2020-1449
https://notcve.org/view.php?id=CVE-2020-1449
A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka 'Microsoft Project Remote Code Execution Vulnerability'. Se presenta una vulnerabilidad de ejecución de código remota en el software Microsoft Project cuando el software presenta un fallo al comprobar el marcado de origen de un archivo, también se conoce como "Microsoft Project Remote Code Execution Vulnerability" • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1449 • CWE-346: Origin Validation Error •
CVE-2020-1322
https://notcve.org/view.php?id=CVE-2020-1322
An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due to an uninitialized variable, aka 'Microsoft Project Information Disclosure Vulnerability'. Se presenta una vulnerabilidad de divulgación de información cuando Microsoft Project lee la memoria fuera del límite debido a una variable no inicializada, también se conoce como "Microsoft Project Information Disclosure Vulnerability" • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1322 • CWE-125: Out-of-bounds Read CWE-908: Use of Uninitialized Resource •
CVE-2020-0954
https://notcve.org/view.php?id=CVE-2020-0954
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0923, CVE-2020-0924, CVE-2020-0925, CVE-2020-0926, CVE-2020-0927, CVE-2020-0930, CVE-2020-0933, CVE-2020-0973, CVE-2020-0978. Hay una vulnerabilidad de tipo cross-site-scripting (XSS) cuando Microsoft SharePoint Server no sanea apropiadamente una petición web especialmente diseñada para un servidor SharePoint afectado, también se conoce como "Microsoft Office SharePoint XSS Vulnerability". Este ID de CVE es diferente de CVE-2020-0923, CVE-2020-0924, CVE-2020-0925, CVE-2020-0926, CVE-2020-0927, CVE-2020-0930, CVE-2020-0933, CVE-2020-0973, CVE-2020-0978. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0954 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •