Skip to content
Noroxi

iatek records

11 published records for vendor iatek.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

11 records
  • user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.

    CriticalCVSS 10.0No exploitEPSS 2%

    iatek · portalappDec 31, 2002

  • CVE-2005-1011
    31Monitor

    SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via the sortby parameter.

    HighCVSS 7.5Proof of conceptEPSS 2%

    iatek · siteenableMay 2, 2005

  • CVE-2005-0948
    30Monitor

    SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parame

    HighCVSS 7.5Proof of conceptEPSS 1%

    iatek · portalappMay 2, 2005

  • CVE-2008-1430
    30Monitor

    SQL injection vulnerability in links.asp in ASPapp allows remote attackers to execute arbitrary SQL commands via the CatId parameter.

    HighCVSS 7.5Proof of conceptEPSS 1%

    iatek · aspappMar 20, 2008

  • CVE-2005-4482
    28Monitor

    Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or

    MediumCVSS 6.8Proof of conceptEPSS 2%

    iatek · portalappDec 22, 2005

  • CVE-2004-1786
    21Monitor

    PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensi

    MediumCVSS 5.0Proof of conceptEPSS 3%

    iatek · portalappJan 4, 2004

  • CVE-2005-4485
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or H

    MediumCVSS 4.3Proof of conceptEPSS 3%

    iatek · projectappDec 22, 2005

  • CVE-2005-4483
    18Monitor

    Cross-site scripting (XSS) vulnerability in login.asp in SiteEnable 3.3 and earlier allows remote attackers to inject arbitrary web script o

    MediumCVSS 4.3Proof of conceptEPSS 2%

    iatek · siteenableDec 22, 2005

  • CVE-2005-4484
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 and earlier allow remote attackers to inject arbitrary web script or

    MediumCVSS 4.3Proof of conceptEPSS 2%

    iatek · intranetappDec 22, 2005

  • CVE-2005-0949
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script

    MediumCVSS 4.3No exploitEPSS 1%

    iatek · portalappMay 2, 2005

  • CVE-2005-1012
    17Monitor

    Cross-site scripting (XSS) vulnerability in Iatek SiteEnable allows remote attackers to inject arbitrary web script or HTML via (1) the cont

    MediumCVSS 4.3No exploitEPSS 1%

    iatek · siteenableMay 2, 2005