Portail Web Php is a narrowly scoped web portal product that recurs in vulnerability disclosures centered on application-layer input-handling and code-generation flaws. The recurring weakness classes—code injection, path traversal, cross-site scripting, and SQL injection—reflect the characteristic risks of PHP-based web applications where user input flows directly into dynamic code execution and database queries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Portail Web Php over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0645HIGH Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) confi | Feb 7, 2008 | 7.5 | 51 | NO | YES |
CVE-2007-0699HIGH PHP remote file inclusion vulnerability in includes/includes.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) before 2.5.1.1 allows remote attackers to exe | Feb 4, 2007 | 7.5 | 29 | NO | YES |
CVE-2008-1068MEDIUM Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the site_path parameter | Feb 28, 2008 | 6.8 | 26 | NO | YES |
CVE-2002-2277HIGH SQL injection vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to execute arbitrary SQL commands via the (1) $rech, (2) $BD_Tab_docs, (3) $BD_Tab_fi | Dec 31, 2002 | 7.5 | 19 | NO | NO |
CVE-2007-0700MEDIUM Directory traversal vulnerability in index.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allows remote attackers to read arbitrary files via a .. (dot d | Feb 4, 2007 | 5.0 | 16 | NO | NO |
CVE-2002-2278MEDIUM Cross-site scripting (XSS) vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to inject arbitrary web script or HTML via the (1) $App_Theme, (2) $Rub_ | Dec 31, 2002 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Portail Web Php.
Media articles that mention a CVE ID that affects a product developed by Portail Web Php — matched by CVE ID, not by vendor name.