Codeworx Technologies
Codeworx Technologies Dcp-portal: vulnerabilidades y CVE
Codeworx Technologies Dcp-portal tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2006-4836 | Media (5.1) | 2.1% | — | 15 sept 2006 | SQL injection vulnerability in login.php in DCP-Portal SE 6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: The lostpassword.php and calendar.php vectors are already covered… |
| CVE-2006-4837 | Alta (7.5) | 2.8% | — | 15 sept 2006 | Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php and (2) library/editor/editor.php.… |
| CVE-2006-4838 | Media (4.3) | 4.1% | — | 15 sept 2006 | Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) root_url and (2) dcp_version parameters in (a) admin/inc/footer.inc.php,… |
| CVE-2006-1120 | Baja (2.6) | 3.0% | — | 9 mar 2006 | Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) its_url parameter in the… |
| CVE-2006-0220 | Media (4.3) | 1.1% | — | 16 ene 2006 | Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3 through 6.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the day parameter in calendar.php and (2) the input form in… |
| CVE-2005-4227 | Alta (7.5) | 3.1% | — | 14 dic 2005 | Multiple "potential" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters in advertiser.php, (2) the aid parameter… |
| CVE-2005-3365 | Alta (7.5) | 3.2% | — | 30 oct 2005 | Multiple SQL injection vulnerabilities in DCP-Portal 6 and earlier allow remote attackers to execute arbitrary SQL commands, possibly requiring encoded characters, via (1) the name parameter in register.php, (2) the… |
| CVE-2005-0454 | Alta (7.5) | 1.5% | — | 2 may 2005 | Multiple SQL injection vulnerabilities in DCP-Portal 6.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the lcat, doc, or uid parameters to index.php, or (2) the mid or bid parameters to… |
| CVE-2004-2511 | Media (4.3) | 5.3% | — | 31 dic 2004 | Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the year, (2) month, and (3) day parameters in calendar.php; (4)… |
| CVE-2004-2512 | Media (4.3) | 4.6% | — | 31 dic 2004 | CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in… |
| CVE-2002-0281 | Media (5.1) | 1.3% | — | 31 may 2002 | Cross-site scripting vulnerability in DCP-Portal 4.2 and earlier allows remote attackers to gain privileges of other portal users by providing Javascript in the job information field to user_update.php. |
| CVE-2002-0282 | Media (5) | 1.7% | — | 31 may 2002 | DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to add_user.php, or via an invalid new_language parameter in (2) contents.php, (3) categories.php, or… |