VendorsArab Portalarab_portal2.1
Vulnerabilities

Arab Portal Arab Portal 2.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2009-2781
SQL injection vulnerability in forum.php in Arab Portal 2.x, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the qc parameter in an addcomment action, a different vector than CVE-2006-1666.
Published 2009-08-17 · Modified
6.01 PoCEPSS 0.007
CVE-2008-5787
Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, in conjunction with a show action.
Published 2008-12-31 · Modified
5.41 PoCEPSS 0.030