Maxwebportal operates a web portal product with exposure concentrated in a small, focused vulnerability footprint that has attracted a notable tendency toward public exploit code availability. The durable signal centers on input-handling weakness classes, particularly SQL injection, which recur across the product line and reflect the attack surface inherent to web application platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maxwebportal over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1213HIGH The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive | Dec 31, 2003 | 7.5 | 35 | NO | YES |
CVE-2004-0271MEDIUM Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showa | Nov 23, 2004 | 6.8 | 32 | NO | YES |
CVE-2009-3436HIGH Multiple SQL injection vulnerabilities in forum.asp in MaxWebPortal allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID or (2) CAT_ID parameter. NOTE: th | Sep 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2005-1779HIGH SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter. | May 31, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-1417HIGH Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) argum | May 3, 2005 | 7.5 | 28 | NO | YES |
CVE-2004-0272HIGH SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages. | Nov 23, 2004 | 7.5 | 24 | NO | NO |
CVE-2003-1212HIGH MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new to | Dec 31, 2003 | 7.5 | 24 | NO | NO |
CVE-2005-1561MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) | May 11, 2005 | 4.3 | 22 | NO | YES |
CVE-2005-1562HIGH Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.a | May 11, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-1017HIGH SQL injection vulnerability in the Update_Events function in events_functions.asp in MaxWebPortal 1.33 and earlier allows remote attackers to execute arbitrary SQL commands via the | May 2, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maxwebportal.
Media articles that mention a CVE ID that affects a product developed by Maxwebportal — matched by CVE ID, not by vendor name.