Portalapp operates a web-based portal application whose vulnerability surface centers on authentication and input-handling weaknesses, including improper authentication, cross-site scripting, and SQL injection. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Portalapp over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4614HIGH PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topics, and replies. | Oct 20, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-4613HIGH SQL injection vulnerability in forums.asp in PortalApp 4.0 allows remote attackers to execute arbitrary SQL commands via the sortby parameter. | Oct 20, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4615HIGH Unspecified vulnerability in i_utils.asp in PortalApp before 4.01a has unknown impact and attack vectors. | Oct 20, 2008 | 10.0 | 24 | NO | NO |
CVE-2008-4612MEDIUM Cross-site scripting (XSS) vulnerability in PortalApp 4.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp and (2) conten | Oct 20, 2008 | 4.3 | 21 | NO | YES |
CVE-2007-3252HIGH PortalApp stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for 8691.mdb, | Jun 18, 2007 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Portalapp.
Media articles that mention a CVE ID that affects a product developed by Portalapp — matched by CVE ID, not by vendor name.