Known Vulnerabilities for products from Powerportal
Listed below are 8 of the newest known vulnerabilities associated with the vendor "Powerportal".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2008-4361 json | Directory traversal vulnerability in PowerPortal 2.0.13 allows remote attackers to list and possibly read arbitrary files via... | Not Provided | 2008-09-30 | 2026-04-23 |
| CVE-2006-5169 json | Cross-site scripting (XSS) vulnerability in John Himmelman (aka DaRk2k1) PowerPortal 1.1 allows remote attackers to inject ar... | Not Provided | 2006-10-10 | 2026-04-23 |
| CVE-2006-5126 json | PHP remote file inclusion vulnerability in index.php in John Himmelman (aka DaRk2k1) PowerPortal 1.3a allows remote attackers... | Not Provided | 2006-10-03 | 2026-04-23 |
| CVE-2006-0358 json | Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbit... | Not Provided | 2006-01-22 | 2025-04-03 |
| CVE-2004-2514 json | Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attackers to ... | Not Provided | 2004-12-31 | 2025-04-03 |
| CVE-2004-0664 json | Directory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directories via... | Not Provided | 2004-08-06 | 2025-04-03 |
| CVE-2004-0663 json | Cross-site scripting (XSS) vulnerability in modules.php in PowerPortal 1.x allows remote attackers to inject arbitrary script... | Not Provided | 2004-08-06 | 2025-04-03 |
| CVE-2004-0662 json | PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests to (... | Not Provided | 2004-08-06 | 2025-04-03 |