MidnightBSD

Advisories for maxwebportal

CVE-2003-1213 HIGH

The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
maxwebportal maxwebportal 1.30
CVE-2004-0271 MEDIUM

Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
maxwebportal maxwebportal 1.31
maxwebportal maxwebportal 1.30
CVE-2004-0272 HIGH

SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
maxwebportal maxwebportal 1.31
maxwebportal maxwebportal 1.30
CVE-2005-1016 MEDIUM

Cross-site scripting (XSS) vulnerability in links_add_form.asp for MaxWebPortal 1.33 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URL in a banner URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
maxwebportal maxwebportal *
CVE-2005-1017 HIGH

SQL injection vulnerability in the Update_Events function in events_functions.asp in MaxWebPortal 1.33 and earlier allows remote attackers to execute arbitrary SQL commands via the EVENT_ID parameter, as demonstrated using events.asp.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
maxwebportal maxwebportal *
CVE-2005-1417 HIGH

Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) arguments to dl_popular.asp, (3) arguments to links_popular.asp, (4) arguments to pic_popular.asp, (5) article_rate.asp, (6) dl_rate.asp, (7) links_rate.asp, (8) pic_rates.asp, (9) article_toprated.asp, (10) dl_toprated.asp, (11) links_toprated.asp, (12) arguments to pic_toprated.asp, or (13) the TOPIC_ID or Forum_ID parameters to custom_link.asp.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
maxwebportal maxwebportal 1.3.5
maxwebportal maxwebportal 2.0
maxwebportal maxwebportal 1.3.2
maxwebportal maxwebportal 1.3.3
maxwebportal maxwebportal 1.3.0
maxwebportal maxwebportal 1.3.1
CVE-2005-1561 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
maxwebportal maxwebportal 1.3.5
maxwebportal maxwebportal 1.3.2
maxwebportal maxwebportal 1.3.3
maxwebportal maxwebportal 1.3.0
maxwebportal maxwebportal 1.3.1
CVE-2005-1562 HIGH

Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.asp, (2) txtAddress, (3) message, or (4) subject parameter to post_info.asp, (5) andor parameter to search.asp, (6) verkey parameter to pop_profile.asp, or (7) Remove or (8) Delete parameter to pm_delete2.asp.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
maxwebportal maxwebportal 1.3.5
maxwebportal maxwebportal 2.0
maxwebportal maxwebportal 1.31
maxwebportal maxwebportal 1.3.2
maxwebportal maxwebportal 1.30
maxwebportal maxwebportal 1.3.3
maxwebportal maxwebportal 1.3.0
maxwebportal maxwebportal 1.3.1
CVE-2005-1779 HIGH

SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
maxwebportal maxwebportal 2.0
maxwebportal maxwebportal 1.36
maxwebportal maxwebportal 2005-04-18
maxwebportal maxwebportal 1.35