RSS   Vulnerabilities for 'Phportal'   RSS

2009-06-18
 
CVE-2009-2117

CWE-287
 

 
uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username.

 
2007-09-18
 
CVE-2007-4950

CWE-94
 

 
** DISPUTED ** PHP remote file inclusion vulnerability in form/db_form/employee.php in PHPortal 0.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. NOTE: this issue is disputed by CVE, since DOCUMENT_ROOT cannot be modified by an attacker.

 


Copyright 2024, cxsecurity.com

 

Back to Top