Portalapp
by Iatek
CVEs (5)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2005-4482 | 0.03 | — | 0.03 | Dec 22, 2005 | Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter. | ||
| CVE-2005-0948 | 0.03 | — | 0.02 | May 2, 2005 | SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter. | ||
| CVE-2004-1786 | 0.03 | — | 0.05 | Jan 4, 2004 | PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb. | ||
| CVE-2005-0949 | 0.00 | — | 0.01 | May 2, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2) keywords parameter. | ||
| CVE-2002-1659 | 0.00 | — | 0.00 | Dec 31, 2002 | user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable. |
- CVE-2005-4482Dec 22, 2005risk 0.03cvss —epss 0.03
Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.
- CVE-2005-0948May 2, 2005risk 0.03cvss —epss 0.02
SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter.
- CVE-2004-1786Jan 4, 2004risk 0.03cvss —epss 0.05
PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.
- CVE-2005-0949May 2, 2005risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2) keywords parameter.
- CVE-2002-1659Dec 31, 2002risk 0.00cvss —epss 0.00
user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.