Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown
CVE-2009-3436
Disclosure Date: September 28, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in forum.asp in MaxWebPortal allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID or (2) CAT_ID parameter. NOTE: this might overlap CVE-2005-1417.
0
Attacker Value
Unknown
CVE-2009-1444
Disclosure Date: April 27, 2009 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.
0
Attacker Value
Unknown
CVE-2008-4345
Disclosure Date: September 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the aid parameter.
0
Attacker Value
Unknown
CVE-2008-0141
Disclosure Date: January 08, 2008 (last updated February 09, 2024)
actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.
0
Attacker Value
Unknown
CVE-2008-0142
Disclosure Date: January 08, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecified other vectors.
0
Attacker Value
Unknown
CVE-2007-6664
Disclosure Date: January 04, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in WebPortal CMS 0.6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter.
0
Attacker Value
Unknown
CVE-2006-4012
Disclosure Date: August 07, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in circeOS SaveWeb Portal 3.4 allow remote attackers to execute arbitrary PHP code via a URL in the SITE_Path parameter to (1) poll/poll.php or (2) poll/view_polls.php. NOTE: the menu_dx.php vector is already covered by CVE-2005-2687.
0
Attacker Value
Unknown
CVE-2005-2687
Disclosure Date: August 24, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in SaveWebPortal 3.4 allows remote attackers to execute arbitrary PHP code via the (1) SITE_Path parameter to menu_dx.php or (2) CONTENTS_Dir parameter to menu_sx.php.
0
Attacker Value
Unknown
CVE-2005-2685
Disclosure Date: August 24, 2005 (last updated February 22, 2025)
SaveWebPortal 3.4 allows remote attackers to execute arbitrary PHP code via a direct request to admin/PhpMyExplorer/editerfichier.php, then editing the desired file to contain the PHP code, as demonstrated using header.php in the fichier parameter. NOTE: it is possible that this vulnerability stems from PhpMyExplorer, which is a separate package.
0
Attacker Value
Unknown
CVE-2005-2686
Disclosure Date: August 24, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in SaveWebPortal 3.4 allows remote attackers to include arbitrary files and execute arbitrary local PHP programs via ".." sequences in the (1) SITE_Path parameter to menu_dx.php or (2) CONTENTS_Dir parameter to menu_sx.php.
0