CVE Vulnerabilities

CVE-2004-0272

Published: Nov 23, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.

Affected Software

Name Vendor Start Version End Version
Maxwebportal Maxwebportal 1.30 (including) 1.30 (including)
Maxwebportal Maxwebportal 1.31 (including) 1.31 (including)

References