Codeworx Technologies maintains a focused product line centered on the DCP Portal, a web-facing administrative and management platform that has attracted a meaningful volume of public exploit tooling despite a modest CVE footprint. The recurring weakness pattern points to SQL injection and related input-neutralization flaws, reflecting the application-layer validation demands of portal-based credential and configuration management surfaces. Defenders should prioritize patches for this vendor given the public exploit availability and the platform's typical deployment in trusted network segments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codeworx Technologies over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2511MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the year, (2) month, and ( | Dec 31, 2004 | 4.3 | 28 | NO | YES |
CVE-2006-4836MEDIUM SQL injection vulnerability in login.php in DCP-Portal SE 6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: The lostpassword.php and | Sep 15, 2006 | 5.1 | 23 | NO | YES |
CVE-2006-4838MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) root_url and (2) dcp_version para | Sep 15, 2006 | 4.3 | 22 | NO | YES |
CVE-2004-2512MEDIUM CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web | Dec 31, 2004 | 4.3 | 22 | NO | YES |
CVE-2006-4837HIGH Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php | Sep 15, 2006 | 7.5 | 20 | NO | NO |
CVE-2005-4227HIGH Multiple "potential" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters i | Dec 14, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-3365HIGH Multiple SQL injection vulnerabilities in DCP-Portal 6 and earlier allow remote attackers to execute arbitrary SQL commands, possibly requiring encoded characters, via (1) the name | Oct 30, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-0454HIGH Multiple SQL injection vulnerabilities in DCP-Portal 6.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the lcat, doc, or uid parameters to index.ph | May 2, 2005 | 7.5 | 19 | NO | NO |
CVE-2002-0282MEDIUM DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to add_user.php, or via an invalid new_language parameter in ( | May 31, 2002 | 5.0 | 19 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML vi | Mar 9, 2006 | 2.6 | 18 | NO | YES |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codeworx Technologies.
Media articles that mention a CVE ID that affects a product developed by Codeworx Technologies — matched by CVE ID, not by vendor name.