Critical severity9.8NVD Advisory· Published Oct 29, 2018· Updated Jun 17, 2026
CVE-2016-10731
CVE-2016-10731
Description
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status, process-zip-download.php with the request parameter file, or home-log.php with the request parameter action.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<= r582+ 2 more
- (no CPE)range: <= r582
- cpe:2.3:a:projectsend:projectsend:582:*:*:*:*:*:*:*
- (no CPE)range: r582
- Range: r582
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.