VYPR

by Limesurvey

Source repositories

CVEs (24)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2011-37520.000.00Sep 23, 2011LimeSurvey 1.90+ build9642-20101214 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/statistics.php and certain other files.
CVE-2009-16040.000.01May 11, 2009Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive data via unknown attack vectors related to /admin/remotecontrol/.
CVE-2008-25710.000.00Jun 6, 2008Cross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly PHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas as administrators via a "modify quota" action.
CVE-2008-25700.000.00Jun 6, 2008Multiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) before 1.71 have unknown impact and attack vectors.

Page 2 of 2