Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) iNews, (2) iType, or (3) Action parameter. NOTE: the iType parameter in type.asp is covered by CVE-2005-3976.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Duamazon | Duware | 3.0 (including) | 3.0 (including) |
Duamazon | Duware | 3.1 (including) | 3.1 (including) |
Duarticle | Duware | 1.0 (including) | 1.0 (including) |
Duarticle | Duware | 1.1 (including) | 1.1 (including) |
Duclassified | Duware | 4.0 (including) | 4.0 (including) |
Duclassified | Duware | 4.1 (including) | 4.1 (including) |
Duclassified | Duware | 4.2 (including) | 4.2 (including) |
Dudirectory | Duware | 3.0 (including) | 3.0 (including) |
Dudirectory | Duware | 3.1 (including) | 3.1 (including) |
Dudirectory_pro | Duware | 3.0 (including) | 3.0 (including) |
Dudirectory_pro | Duware | 3.1 (including) | 3.1 (including) |
Dudirectory_pro_sql | Duware | 3.0 (including) | 3.0 (including) |
Dudirectory_pro_sql | Duware | 3.1 (including) | 3.1 (including) |
Dudownload | Duware | 1.0 (including) | 1.0 (including) |
Dudownload | Duware | 1.1 (including) | 1.1 (including) |
Dugallery | Duware | 3.0 (including) | 3.0 (including) |
Dugallery | Duware | 3.1 (including) | 3.1 (including) |
Dugallery | Duware | 3.2 (including) | 3.2 (including) |
Dugallery | Duware | 3.3 (including) | 3.3 (including) |
Dunews | Duware | 1.0 (including) | 1.0 (including) |
Dunews | Duware | 1.1 (including) | 1.1 (including) |
Dupaypal | Duware | 3.0 (including) | 3.0 (including) |
Dupaypal | Duware | 3.1 (including) | 3.1 (including) |
Dupaypal_pro | Duware | 3.0 (including) | 3.0 (including) |
Dupaypal_pro | Duware | 3.1 (including) | 3.1 (including) |