7.5
CVSSv2

CVE-2003-1213

Published: 31/12/2003 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote malicious users to obtain sensitive information via a direct request to database/db2000.mdb.

Vulnerable Product Search on Vulmon Subscribe to Product

maxwebportal maxwebportal 1.30

Exploits

source: wwwsecurityfocuscom/bid/7837/info A number of vulnerabilities have been discovered in the MaxWebPortal The issues that have been discovered include: MaxWebPortal 'searchasp' has been reported prone to a cross-site scripting vulnerability An attacker may execute arbitrary script code in the security context of the system ru ...