Skip to main content

Vendor/product archive

codeworx_technologies / dcp-portal CVEs

Beta · best-effort

12 CVEs tagged to codeworx_technologies / dcp-portal0 Critical, 4 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2006-4836

Published Sep 15, 2006

SQL injection vulnerability in login.php in DCP-Portal SE 6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: The lostpassword.php and…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4837

Published Sep 15, 2006

Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4838

Published Sep 15, 2006

Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) root_url and (2) dcp_version par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1120

Published Mar 9, 2006

Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML v…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-0220

Published Jan 16, 2006

Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3 through 6.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the day parameter in cale…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4227

Published Dec 14, 2005

Multiple "potential" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3365

Published Oct 30, 2005

Multiple SQL injection vulnerabilities in DCP-Portal 6 and earlier allow remote attackers to execute arbitrary SQL commands, possibly requiring encoded characters, via (1) the nam…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0454

Published May 2, 2005

Multiple SQL injection vulnerabilities in DCP-Portal 6.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the lcat, doc, or uid parameters to index.p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2511

Published Dec 31, 2004

Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the year, (2) month, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2512

Published Dec 31, 2004

CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0281

Published May 31, 2002

Cross-site scripting vulnerability in DCP-Portal 4.2 and earlier allows remote attackers to gain privileges of other portal users by providing Javascript in the job information fi…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0282

Published May 31, 2002

DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to add_user.php, or via an invalid new_language parameter in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1