Vulnerabilities
Vulnerable Software
Portalapp:  >> Portalapp  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in PortalApp 4.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp and (2) content.asp.
CVSS Score
4.3
EPSS Score
0.053
Published
2008-10-20
SQL injection vulnerability in forums.asp in PortalApp 4.0 allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
CVSS Score
7.5
EPSS Score
0.004
Published
2008-10-20
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topics, and replies.
CVSS Score
7.5
EPSS Score
0.044
Published
2008-10-20
Unspecified vulnerability in i_utils.asp in PortalApp before 4.01a has unknown impact and attack vectors.
CVSS Score
10.0
EPSS Score
0.003
Published
2008-10-20
PortalApp stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for 8691.mdb, a different vector than CVE-2004-1786.
CVSS Score
7.8
EPSS Score
0.003
Published
2007-06-18


Contact Us

Shodan ® - All rights reserved