Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown

CVE-2020-23715

Disclosure Date: June 28, 2021 (last updated February 22, 2025)
Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download.
Attacker Value
Unknown

CVE-2020-18667

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn.
Attacker Value
Unknown

CVE-2019-13557

Disclosure Date: November 08, 2019 (last updated November 27, 2024)
In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker to access system and configuration information.
Attacker Value
Unknown

CVE-2009-3436

Disclosure Date: September 28, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in forum.asp in MaxWebPortal allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID or (2) CAT_ID parameter. NOTE: this might overlap CVE-2005-1417.
0
Attacker Value
Unknown

CVE-2009-1445

Disclosure Date: April 27, 2009 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary files via directory traversal sequences in the lang parameter to libraries/helpdocs/help.php and (2) include and execute arbitrary local files via directory traversal sequences in the error parameter to index.php.
0
Attacker Value
Unknown

CVE-2009-1444

Disclosure Date: April 27, 2009 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.
0
Attacker Value
Unknown

CVE-2008-4345

Disclosure Date: September 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the aid parameter.
0
Attacker Value
Unknown

CVE-2008-0141

Disclosure Date: January 08, 2008 (last updated February 09, 2024)
actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.
Attacker Value
Unknown

CVE-2008-0142

Disclosure Date: January 08, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecified other vectors.
0
Attacker Value
Unknown

CVE-2007-6664

Disclosure Date: January 04, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in WebPortal CMS 0.6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter.
0