Multiple MaxWebPortal Vulnerabilities

BID:7837

Info

Multiple MaxWebPortal Vulnerabilities

Bugtraq ID: 7837
Class: Unknown
CVE:
Remote: Yes
Local: No
Published: Jun 06 2003 12:00AM
Updated: Jun 06 2003 12:00AM
Credit: Discovery of this vulnerability has been credited to JeiAr <[email protected]>.
Vulnerable: MaxWebPortal MaxWebPortal 1.30
Not Vulnerable:

Discussion

Multiple MaxWebPortal Vulnerabilities

A number of vulnerabilities have been discovered in the MaxWebPortal.

The issues that have been discovered include:

MaxWebPortal 'search.asp' has been reported prone to a cross-site scripting vulnerability. An attacker may execute arbitrary script code in the security context of the system running MaxWebPortal.

MaxWebPortal has been reported prone to insecure hidden form field vulnerability. An attacker may save the 'start new topic' page offline. By modifying certain field values, the attacker may corrupt the MaxWebPortal contents.

MaxWebPortal has also been reported prone to insecure session cookie vulnerability. Reportedly if an attacker can retrieve a session cookie for a legitimate MaxWebPortal user, the attacker may hijack the account.

MaxWebPortal has been reported prone to a database disclosure vulnerability. MaxWebPortal does not sufficiently secure the database file. It is possible for remote attackers to request the database file and gain access to sensitive information.

MaxWebPortal 'password.asp' has been reported prone to a password-reset vulnerability. It has been reported that by requesting a forgotten password, an attacker may save the 'password reset' page offline. By modifying the member id in the script the attacker may reset arbitrary account passwords.

Exploit / POC

Multiple MaxWebPortal Vulnerabilities

The following proof of concept has been supplied:

http://www.example.com/search.asp?Search=">&lt;script&gt;alert()&lt;/script&gt;
http://www.example.com/database/db2000.mdb

Solution / Fix

Multiple MaxWebPortal Vulnerabilities

Solution:
The vendor has released a fix to address this issue:


MaxWebPortal MaxWebPortal 1.30

References

Multiple MaxWebPortal Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report