SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: the iState parameter is already covered by CVE-2005-3976 and the iPro parameter is already covered by CVE-2005-2047.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dupaypal | Duware | 3.0 (including) | 3.0 (including) |
Dupaypal | Duware | 3.1 (including) | 3.1 (including) |
Dupaypal | Duware | pro_3.0 (including) | pro_3.0 (including) |
Dupaypal | Duware | pro_3.1 (including) | pro_3.1 (including) |