VYPR
Critical severity9.8NVD Advisory· Published Oct 29, 2018· Updated Jun 17, 2026

CVE-2016-10731

CVE-2016-10731

Description

ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status, process-zip-download.php with the request parameter file, or home-log.php with the request parameter action.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Projectsend/Projectsendinferred3 versions
    <= r582+ 2 more
    • (no CPE)range: <= r582
    • cpe:2.3:a:projectsend:projectsend:582:*:*:*:*:*:*:*
    • (no CPE)range: r582
  • Projectsend/cFTPllm-create
    Range: r582

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.