Powerportal operates a niche portal application that, despite modest disclosure volume, occupies a notable position within its deployment context. The vendor's vulnerability profile centers on path-traversal conditions and related directory-access weaknesses that are characteristic of file-serving and content-management portal architectures, and public exploit code has frequently been made available for its disclosed issues. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Powerportal over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4361HIGH Directory traversal vulnerability in PowerPortal 2.0.13 allows remote attackers to list and possibly read arbitrary files via a .. (dot dot) in the path parameter to the default UR | Sep 30, 2008 | 7.8 | 29 | NO | YES |
CVE-2006-5126HIGH PHP remote file inclusion vulnerability in index.php in John Himmelman (aka DaRk2k1) PowerPortal 1.3a allows remote attackers to execute arbitrary PHP code via a URL in the file_na | Oct 3, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-0358HIGH Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index | Jan 22, 2006 | 7.5 | 28 | NO | YES |
CVE-2004-2514MEDIUM Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attackers to inject arbitrary web script or HTML via the (1) SUBJECT | Dec 31, 2004 | 4.3 | 26 | NO | YES |
CVE-2004-0664MEDIUM Directory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directories via a .. (dot dot) in the files parameter. | Aug 6, 2004 | 5.0 | 25 | NO | YES |
CVE-2004-0663MEDIUM Cross-site scripting (XSS) vulnerability in modules.php in PowerPortal 1.x allows remote attackers to inject arbitrary script or HTML via the (1) id parameter to the (a) private_me | Aug 6, 2004 | 6.8 | 18 | NO | NO |
CVE-2006-5169MEDIUM Cross-site scripting (XSS) vulnerability in John Himmelman (aka DaRk2k1) PowerPortal 1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, pos | Oct 10, 2006 | 5.1 | 15 | NO | NO |
CVE-2004-0662MEDIUM PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests to (1) resize.php or (2) modules.php, which reveals the pat | Aug 6, 2004 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Powerportal.
Media articles that mention a CVE ID that affects a product developed by Powerportal — matched by CVE ID, not by vendor name.