Douran's vulnerability profile is concentrated in a narrow set of web-facing and gateway products—including DSGate, FollowWeb, and Portal—where the disclosed issues center on sensitive information exposure and access-control weaknesses characteristic of authentication and data-handling flaws. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Douran over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-1569MEDIUM download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web root via (1) a trailing ".", (2) a trailing space, or (3) mixe | Apr 5, 2011 | 5.0 | 28 | NO | YES |
CVE-2023-38996MEDIUM An issue in all versions of Douran DSGate allows a local authenticated privileged attacker to execute arbitrary code via the debug command. | Aug 22, 2023 | 6.7 | 18 | NO | NO |
CVE-2006-0373MEDIUM Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the | Jan 22, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Douran.
Media articles that mention a CVE ID that affects a product developed by Douran — matched by CVE ID, not by vendor name.