Arabportal maintains a web application portal product that, despite a narrow footprint, exhibits recurring application-layer input-handling vulnerabilities concentrated in SQL injection and path-traversal weaknesses. The product's vulnerability profile demonstrates a strong tendency toward public exploit availability, reflecting the accessibility of web-facing applications to security research and tooling. Defenders should prioritize patch cycles for this portal and apply input-validation hardening; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arabportal over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-6519HIGH SQL injection vulnerability in Arab Portal 3 allows remote attackers to execute arbitrary SQL commands via the showemail parameter in a signup action to members.php. | Aug 18, 2015 | 7.5 | 28 | NO | YES |
CVE-2010-2340MEDIUM SQL injection vulnerability in members.php in Arab Portal 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the by parameter in | Jun 18, 2010 | 6.8 | 28 | NO | YES |
CVE-2009-4203HIGH Multiple SQL injection vulnerabilities in admin/aclass/admin_func.php in Arab Portal 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) X-Forwarded-For or (2) | Dec 4, 2009 | 7.5 | 28 | NO | YES |
CVE-2005-4221HIGH SQL injection vulnerability in link.php in Arab Portal System 2 Beta 2 allows remote attackers to execute arbitrary SQL commands via the (1) PHPSESSID (session ID) or (2) REQUEST_U | Dec 14, 2005 | 7.5 | 28 | NO | YES |
CVE-2006-1504MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the | Mar 30, 2006 | 5.1 | 25 | NO | YES |
CVE-2009-2781MEDIUM SQL injection vulnerability in forum.php in Arab Portal 2.x, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the qc param | Aug 17, 2009 | 6.0 | 24 | NO | YES |
CVE-2008-5787MEDIUM Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, in conjunction | Dec 31, 2008 | 5.4 | 24 | NO | YES |
CVE-2009-4725MEDIUM Directory traversal vulnerability in modules/aljazeera/admin/setup.php in Arab Portal 2.2 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows rem | Mar 18, 2010 | 5.1 | 23 | NO | YES |
CVE-2006-1666HIGH SQL injection vulnerability in forum.php in Arab Portal 2.0.1 stable allows remote attackers to execute arbitrary SQL commands via the mineID parameter. | Apr 7, 2006 | 7.5 | 19 | NO | NO |
CVE-2005-2546MEDIUM Arab Portal 2.0 allows remote attackers to obtain sensitive information via a long (1) username or (2) password, which reveals the path in an error message when the undefined "errm | Aug 10, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arabportal.
Media articles that mention a CVE ID that affects a product developed by Arabportal — matched by CVE ID, not by vendor name.