Vulnerabilities (CVE)

Filtered by vendor Iatek Subscribe
Filtered by product Portalapp
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-0948 1 Iatek 1 Portalapp 2023-12-10 7.5 HIGH N/A
SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter.
CVE-2005-4482 1 Iatek 1 Portalapp 2023-12-10 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.
CVE-2005-0949 1 Iatek 1 Portalapp 2023-12-10 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2) keywords parameter.
CVE-2004-1786 1 Iatek 1 Portalapp 2023-12-10 5.0 MEDIUM N/A
PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.
CVE-2002-1659 1 Iatek 1 Portalapp 2023-12-10 10.0 HIGH N/A
user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.