Skip to main content

Vendor/product archive

iatek / portalapp CVEs

Beta · best-effort

5 CVEs tagged to iatek / portalapp1 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2005-4482

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0948

Published May 2, 2005

SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0949

Published May 2, 2005

Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1786

Published Jan 4, 2004

PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1659

Published Dec 31, 2002

user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1