Back

CVE-2004-0272

SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.

Published: Nov 23, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
maxwebportal maxwebportal 1.30
maxwebportal maxwebportal 1.31

GitHub Security Advisory GHSA-pq63-4vgj-rxhv

SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.33%

Top 31% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub