Show filters
24 Total Results
Displaying 21-24 of 24
Sort by:
Attacker Value
Unknown
CVE-2005-1016
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in links_add_form.asp for MaxWebPortal 1.33 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URL in a banner URL.
0
Attacker Value
Unknown
CVE-2004-0272
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.
0
Attacker Value
Unknown
CVE-2004-0271
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form.
0
Attacker Value
Unknown
CVE-2003-1213
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb.
0