CVE Tools

Maxwebportal

9 CVEs tracked since 2004. Since Mar 2004, none of them reached CISA KEV.

Maxwebportal CVEs per month

Mar 2004 to May 2005. Point at a month, or focus the strip and use the arrow keys.
Maxwebportal CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2004-0320
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-02null or fewer
2005-03null or fewer
2005-0420
2005-0550

Products

The products that kept showing up in Maxwebportal's monthly top three, with their CVEs summed over those months.

  1. Maxwebportal93 months

Latest CVEs

The 10 most recently published vulnerabilities affecting Maxwebportal.

  1. CVE-2009-3436Multiple SQL injection vulnerabilities in forum.asp in MaxWebPortal allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID or (2) CAT_ID parameter. NOTE: this might overlap ...7.5
  2. CVE-2005-1779SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.7.5
  3. CVE-2003-1213The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via ...7.5
  4. CVE-2005-1562Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.asp, (2) txtAddres...7.5
  5. CVE-2005-1561Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type p...4.3
  6. CVE-2005-1417Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) arguments to dl_popula...7.5
  7. CVE-2005-1017SQL injection vulnerability in the Update_Events function in events_functions.asp in MaxWebPortal 1.33 and earlier allows remote attackers to execute arbitrary SQL commands via the EVENT_ID paramet...7.5
  8. CVE-2005-1016Cross-site scripting (XSS) vulnerability in links_add_form.asp for MaxWebPortal 1.33 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URL in a banner URL.4.3
  9. CVE-2004-0272SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.7.5
  10. CVE-2004-0271Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the S...6.8

The record

Peak rank
#25 in May 2005
Busiest month shown
May 2005, 5 CVEs
Months with a KEV entry
0 since Mar 2004
Monthly snapshots
3 since 2004
Maxwebportal's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store