CVE Vulnerabilities

CVE-2006-6365

Published: Dec 07, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: the iState parameter is already covered by CVE-2005-3976 and the iPro parameter is already covered by CVE-2005-2047.

Affected Software

NameVendorStart VersionEnd Version
DupaypalDuware3.0 (including)3.0 (including)
DupaypalDuware3.1 (including)3.1 (including)
DupaypalDuwarepro_3.0 (including)pro_3.0 (including)
DupaypalDuwarepro_3.1 (including)pro_3.1 (including)

References