Savewebportal is a web portal application with a compact vulnerability footprint centered on the single product of the same name. The observed weakness classes cluster around generic or miscellaneous input-handling and logic issues typical of web-facing applications. Current severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Savewebportal over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4012MEDIUM Multiple PHP remote file inclusion vulnerabilities in circeOS SaveWeb Portal 3.4 allow remote attackers to execute arbitrary PHP code via a URL in the SITE_Path parameter to (1) po | Aug 7, 2006 | 5.1 | 23 | NO | YES |
CVE-2005-2685HIGH SaveWebPortal 3.4 allows remote attackers to execute arbitrary PHP code via a direct request to admin/PhpMyExplorer/editerfichier.php, then editing the desired file to contain the | Aug 24, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-2686HIGH Directory traversal vulnerability in SaveWebPortal 3.4 allows remote attackers to include arbitrary files and execute arbitrary local PHP programs via ".." sequences in the (1) SIT | Aug 24, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-2687HIGH PHP remote file inclusion vulnerability in SaveWebPortal 3.4 allows remote attackers to execute arbitrary PHP code via the (1) SITE_Path parameter to menu_dx.php or (2) CONTENTS_Di | Aug 24, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-2688MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in SaveWebPortal 3.4 allow remote attackers to inject arbitrary web script or HTML via a large number of parameters to (1) foote | Aug 24, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Savewebportal.
Media articles that mention a CVE ID that affects a product developed by Savewebportal — matched by CVE ID, not by vendor name.