CVE Vulnerabilities

CVE-2005-1417

Published: May 03, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) arguments to dl_popular.asp, (3) arguments to links_popular.asp, (4) arguments to pic_popular.asp, (5) article_rate.asp, (6) dl_rate.asp, (7) links_rate.asp, (8) pic_rates.asp, (9) article_toprated.asp, (10) dl_toprated.asp, (11) links_toprated.asp, (12) arguments to pic_toprated.asp, or (13) the TOPIC_ID or Forum_ID parameters to custom_link.asp.

Affected Software

Name Vendor Start Version End Version
Maxwebportal Maxwebportal 1.3.0 (including) 1.3.0 (including)
Maxwebportal Maxwebportal 1.3.1 (including) 1.3.1 (including)
Maxwebportal Maxwebportal 1.3.2 (including) 1.3.2 (including)
Maxwebportal Maxwebportal 1.3.3 (including) 1.3.3 (including)
Maxwebportal Maxwebportal 1.3.5 (including) 1.3.5 (including)
Maxwebportal Maxwebportal 2.0 (including) 2.0 (including)

References