Vulnerabilities > Jportal
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-03-13 | CVE-2008-6451 | SQL Injection vulnerability in Jportal 2 SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 7.5 |
2007-11-15 | CVE-2007-5974 | SQL Injection vulnerability in Jportal web Portal 2 SQL injection vulnerability in mailer.php in JPortal 2 allows remote attackers to execute arbitrary SQL commands via the to parameter. | 7.5 |
2007-11-15 | CVE-2007-5973 | SQL Injection vulnerability in Jportal web Portal SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter. | 7.5 |
2007-11-10 | CVE-2007-5912 | SQL Injection vulnerability in Jportal web Portal 2 SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the to parameter. | 7.5 |
2007-02-13 | CVE-2007-0912 | Cross-Site Request Forgery vulnerability in Jportal web Server 2.3.1 Cross-Site Request Forgery (CSRF) vulnerability in admin/admin.adm.php in Jportal 2.3.1, and possibly earlier, allows remote attackers to perform privileged actions as administrators by tricking the admin into accessing a URL with modified arguments to admin/admin.adm.php. | 9.3 |
2005-11-06 | CVE-2005-3509 | SQL Injection vulnerability in Jportal web Portal 2.2.1/2.3.1 Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, and (4) news.php. | 7.5 |
2005-09-24 | CVE-2005-3052 | SQL-Injection vulnerability in jportal SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php. | 7.5 |
2005-04-12 | CVE-2005-1071 | SQL injection vulnerability in banner.inc.php in JPortal Web Portal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the haslo parameter. | 7.5 |
2004-05-28 | CVE-2004-2036 | SQL Injection vulnerability in Jportal web Portal 2.2.1 SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter. | 7.5 |