Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) iNews, (2) iType, or (3) Action parameter. NOTE: the iType parameter in type.asp is covered by CVE-2005-3976.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Duamazon | Duware | 3.0 (including) | 3.0 (including) |
| Duamazon | Duware | 3.1 (including) | 3.1 (including) |
| Duarticle | Duware | 1.0 (including) | 1.0 (including) |
| Duarticle | Duware | 1.1 (including) | 1.1 (including) |
| Duclassified | Duware | 4.0 (including) | 4.0 (including) |
| Duclassified | Duware | 4.1 (including) | 4.1 (including) |
| Duclassified | Duware | 4.2 (including) | 4.2 (including) |
| Dudirectory | Duware | 3.0 (including) | 3.0 (including) |
| Dudirectory | Duware | 3.1 (including) | 3.1 (including) |
| Dudirectory_pro | Duware | 3.0 (including) | 3.0 (including) |
| Dudirectory_pro | Duware | 3.1 (including) | 3.1 (including) |
| Dudirectory_pro_sql | Duware | 3.0 (including) | 3.0 (including) |
| Dudirectory_pro_sql | Duware | 3.1 (including) | 3.1 (including) |
| Dudownload | Duware | 1.0 (including) | 1.0 (including) |
| Dudownload | Duware | 1.1 (including) | 1.1 (including) |
| Dugallery | Duware | 3.0 (including) | 3.0 (including) |
| Dugallery | Duware | 3.1 (including) | 3.1 (including) |
| Dugallery | Duware | 3.2 (including) | 3.2 (including) |
| Dugallery | Duware | 3.3 (including) | 3.3 (including) |
| Dunews | Duware | 1.0 (including) | 1.0 (including) |
| Dunews | Duware | 1.1 (including) | 1.1 (including) |
| Dupaypal | Duware | 3.0 (including) | 3.0 (including) |
| Dupaypal | Duware | 3.1 (including) | 3.1 (including) |
| Dupaypal_pro | Duware | 3.0 (including) | 3.0 (including) |
| Dupaypal_pro | Duware | 3.1 (including) | 3.1 (including) |