PT-2002-2383 · Portalapp · Portalapp

Published

2002-12-31

·

Updated

2017-07-11

·

CVE-2002-1659

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PortalApp version 2.2
Description The issue allows local users to gain privileges by modifying the user id variable in the 'user profile.asp' file.
Recommendations For PortalApp version 2.2, avoid using the user id variable in the 'user profile.asp' file until the issue is resolved. As a temporary workaround, consider restricting access to the 'user profile.asp' file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1659

Affected Products

Portalapp