Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2008-4345

Disclosure Date: September 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the aid parameter.
0
Attacker Value
Unknown

CVE-2008-0141

Disclosure Date: January 08, 2008 (last updated February 09, 2024)
actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.