Vulnerabilities > CVE-2006-0358 - Cross-Site Scripting vulnerability in Powerportal 1.1B/1.3/1.3B

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
powerportal
exploit available

Summary

Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2.

Vulnerable Configurations

Part Description Count
Application
Powerportal
3

Exploit-Db

  • descriptionPowerPortal 1.1/1.3 search.php search Parameter XSS. CVE-2006-0358. Webapps exploit for php platform
    idEDB-ID:27103
    last seen2016-02-03
    modified2006-01-17
    published2006-01-17
    reporternight_warrior771
    sourcehttps://www.exploit-db.com/download/27103/
    titlePowerPortal 1.1/1.3 - search.php search Parameter XSS
  • descriptionPowerPortal 1.1/1.3 index.php search Parameter XSS. CVE-2006-0358. Webapps exploit for php platform
    idEDB-ID:27102
    last seen2016-02-03
    modified2006-01-17
    published2006-01-17
    reporternight_warrior771
    sourcehttps://www.exploit-db.com/download/27102/
    titlePowerPortal 1.1/1.3 index.php search Parameter XSS