Jportal
3 CVEs tracked since 2007. Since Nov 2007, none of them reached CISA KEV.
Jportal CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2007-11 | 3 | 0 |
Products
The products that kept showing up in Jportal's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 7 most recently published vulnerabilities affecting Jportal.
- CVE-2008-6451SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2004-2036 or CVE-2005-3509.7.5
- CVE-2007-5974SQL injection vulnerability in mailer.php in JPortal 2 allows remote attackers to execute arbitrary SQL commands via the to parameter.7.5
- CVE-2007-5973SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter.7.5
- CVE-2007-5912SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the to parameter.7.5
- CVE-2007-0912Cross-Site Request Forgery (CSRF) vulnerability in admin/admin.adm.php in Jportal 2.3.1, and possibly earlier, allows remote attackers to perform privileged actions as administrators by tricking th...9.3
- CVE-2005-3509Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, and (4) news.php.7.5
- CVE-2004-2036SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.7.5
The record
- Peak rank
- #27 in Nov 2007
- Busiest month shown
- Nov 2007, 3 CVEs
- Months with a KEV entry
- 0 since Nov 2007
- Monthly snapshots
- 1 since 2007