Vulnerabilities
Vulnerable Software
Arabportal:  >> Arab Portal  >> 2.1  Security Vulnerabilities
SQL injection vulnerability in forum.php in Arab Portal 2.x, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the qc parameter in an addcomment action, a different vector than CVE-2006-1666.
CVSS Score
6.0
EPSS Score
0.002
Published
2009-08-17
Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, in conjunction with a show action.
CVSS Score
5.4
EPSS Score
0.066
Published
2008-12-31


Contact Us

Shodan ® - All rights reserved