Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro parameter to edit.asp.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Duclassmate | Duware | 1.2 (including) | 1.2 (including) |