CVE Vulnerabilities

CVE-2006-6354

Published: Dec 07, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) iNews, (2) iType, or (3) Action parameter. NOTE: the iType parameter in type.asp is covered by CVE-2005-3976.

Affected Software

Name Vendor Start Version End Version
Duamazon Duware 3.0 (including) 3.0 (including)
Duamazon Duware 3.1 (including) 3.1 (including)
Duarticle Duware 1.0 (including) 1.0 (including)
Duarticle Duware 1.1 (including) 1.1 (including)
Duclassified Duware 4.0 (including) 4.0 (including)
Duclassified Duware 4.1 (including) 4.1 (including)
Duclassified Duware 4.2 (including) 4.2 (including)
Dudirectory Duware 3.0 (including) 3.0 (including)
Dudirectory Duware 3.1 (including) 3.1 (including)
Dudirectory_pro Duware 3.0 (including) 3.0 (including)
Dudirectory_pro Duware 3.1 (including) 3.1 (including)
Dudirectory_pro_sql Duware 3.0 (including) 3.0 (including)
Dudirectory_pro_sql Duware 3.1 (including) 3.1 (including)
Dudownload Duware 1.0 (including) 1.0 (including)
Dudownload Duware 1.1 (including) 1.1 (including)
Dugallery Duware 3.0 (including) 3.0 (including)
Dugallery Duware 3.1 (including) 3.1 (including)
Dugallery Duware 3.2 (including) 3.2 (including)
Dugallery Duware 3.3 (including) 3.3 (including)
Dunews Duware 1.0 (including) 1.0 (including)
Dunews Duware 1.1 (including) 1.1 (including)
Dupaypal Duware 3.0 (including) 3.0 (including)
Dupaypal Duware 3.1 (including) 3.1 (including)
Dupaypal_pro Duware 3.0 (including) 3.0 (including)
Dupaypal_pro Duware 3.1 (including) 3.1 (including)

References