VendorsIatekportalappall versions
Vulnerabilities

Iatek Portalapp

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2002-1659
user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.
Published 2005-05-10 · Modified
10.0EPSS 0.018
CVE-2005-0948
SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter.
Published 2005-04-03 · Modified
7.51 PoCEPSS 0.013
CVE-2005-4482
Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.
Published 2005-12-22 · Modified
6.81 PoCEPSS 0.020
CVE-2004-1786
PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.
Published 2005-05-10 · Modified
5.01 PoCEPSS 0.028
CVE-2005-0949
Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2) keywords parameter.
Published 2005-04-03 · Modified
4.3EPSS 0.014