VYPR

Portalapp

by Iatek

CVEs (5)

  • CVE-2005-4482Dec 22, 2005
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.

  • CVE-2005-0948May 2, 2005
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter.

  • CVE-2004-1786Jan 4, 2004
    risk 0.03cvss epss 0.05

    PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.

  • CVE-2005-0949May 2, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2) keywords parameter.

  • CVE-2002-1659Dec 31, 2002
    risk 0.00cvss epss 0.00

    user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.