CVE Vulnerabilities

CVE-2006-6354

Published: Dec 07, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) iNews, (2) iType, or (3) Action parameter. NOTE: the iType parameter in type.asp is covered by CVE-2005-3976.

Affected Software

NameVendorStart VersionEnd Version
DuamazonDuware3.0 (including)3.0 (including)
DuamazonDuware3.1 (including)3.1 (including)
DuarticleDuware1.0 (including)1.0 (including)
DuarticleDuware1.1 (including)1.1 (including)
DuclassifiedDuware4.0 (including)4.0 (including)
DuclassifiedDuware4.1 (including)4.1 (including)
DuclassifiedDuware4.2 (including)4.2 (including)
DudirectoryDuware3.0 (including)3.0 (including)
DudirectoryDuware3.1 (including)3.1 (including)
Dudirectory_proDuware3.0 (including)3.0 (including)
Dudirectory_proDuware3.1 (including)3.1 (including)
Dudirectory_pro_sqlDuware3.0 (including)3.0 (including)
Dudirectory_pro_sqlDuware3.1 (including)3.1 (including)
DudownloadDuware1.0 (including)1.0 (including)
DudownloadDuware1.1 (including)1.1 (including)
DugalleryDuware3.0 (including)3.0 (including)
DugalleryDuware3.1 (including)3.1 (including)
DugalleryDuware3.2 (including)3.2 (including)
DugalleryDuware3.3 (including)3.3 (including)
DunewsDuware1.0 (including)1.0 (including)
DunewsDuware1.1 (including)1.1 (including)
DupaypalDuware3.0 (including)3.0 (including)
DupaypalDuware3.1 (including)3.1 (including)
Dupaypal_proDuware3.0 (including)3.0 (including)
Dupaypal_proDuware3.1 (including)3.1 (including)

References