Vulnerabilities > CVE-2004-2036 - SQL Injection vulnerability in Jportal web Portal 2.2.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
jportal
nessus
exploit available

Summary

SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.

Vulnerable Configurations

Part Description Count
Application
Jportal
1

Exploit-Db

descriptionJPortal 2.2.1 Print.php SQL Injection Vulnerability. CVE-2004-2036. Webapps exploit for php platform
idEDB-ID:24151
last seen2016-02-02
modified2004-05-28
published2004-05-28
reporterMaciek Wierciski
sourcehttps://www.exploit-db.com/download/24151/
titleJPortal 2.2.1 Print.php SQL Injection Vulnerability

Nessus

NASL familyCGI abuses
NASL idJPORTAL_SQL_INJECTION.NASL
descriptionThe remote host appears to be running the jPortal CGI suite. There is a SQL injection vulnerability in the
last seen2020-06-01
modified2020-06-02
plugin id12256
published2004-05-29
reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/12256
titlejPortal print.inc.php id Parameter SQL Injection