Skip to main content

Vendor archive

iatek CVEs

Beta · best-effort

11 CVEs tagged to vendor iatek1 Critical, 3 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2008-1430

Published Mar 20, 2008

SQL injection vulnerability in links.asp in ASPapp allows remote attackers to execute arbitrary SQL commands via the CatId parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4482

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4483

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in login.asp in SiteEnable 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4484

Published Dec 22, 2005

Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ret_page parameter to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4485

Published Dec 22, 2005

Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0948

Published May 2, 2005

SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0949

Published May 2, 2005

Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1011

Published May 2, 2005

SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via the sortby parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1012

Published May 2, 2005

Cross-site scripting (XSS) vulnerability in Iatek SiteEnable allows remote attackers to inject arbitrary web script or HTML via (1) the contenttype parameter to content.asp, (2) t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1786

Published Jan 4, 2004

PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1659

Published Dec 31, 2002

user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1