Skip to content
Noroxi

duware records

23 published records for vendor duware.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
17
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    23 records
    • SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity par

      CriticalCVSS 10.0Proof of conceptEPSS 2%

      duware · duclassmateDec 6, 2006

    • CVE-2005-1224
      31Monitor

      Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChan

      HighCVSS 7.5Proof of conceptEPSS 4%

      duware · duportalMay 2, 2005

    • CVE-2005-2048
      31Monitor

      Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL c

      HighCVSS 7.5Proof of conceptEPSS 2%

      duware · duforumJun 22, 2005

    • CVE-2005-1236
      31Monitor

      Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via t

      HighCVSS 7.5Proof of conceptEPSS 2%

      duware · duportalMay 2, 2005

    • CVE-2005-2049
      31Monitor

      Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState

      HighCVSS 7.5Proof of conceptEPSS 2%

      duware · duclassmateJun 22, 2005

    • CVE-2005-2046
      31Monitor

      Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (

      HighCVSS 7.5Proof of conceptEPSS 2%

      duware · duamazon proJun 22, 2005

    • CVE-2006-6354
      31Monitor

      Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) i

      HighCVSS 7.5No exploitEPSS 2%

      duware · duamazonDec 6, 2006

    • CVE-2006-6367
      30Monitor

      Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbit

      HighCVSS 7.5Proof of conceptEPSS 2%

      duware · dudownloadDec 7, 2006

    • CVE-2004-2202
      30Monitor

      Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute o

      HighCVSS 7.5Proof of conceptEPSS 1%

      duware · duclassifiedDec 31, 2004

    • CVE-2006-6365
      30Monitor

      SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL com

      HighCVSS 7.5Proof of conceptEPSS 1%

      duware · dupaypalDec 7, 2006

    • CVE-2005-2045
      30Monitor

      Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iCh

      HighCVSS 7.5No exploitEPSS 1%

      duware · duportal proJun 22, 2005

    • CVE-2006-6455
      30Monitor

      Multiple SQL injection vulnerabilities in admin/default.asp in DUware DUdirectory 3.1, and possibly DUdirectory Pro and Pro SQL 3.x, allow r

      HighCVSS 7.5No exploitEPSS 1%

      duware · dudirectoryDec 10, 2006

    • CVE-2006-2302
      30Monitor

      SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Logi

      HighCVSS 7.5No exploitEPSS 1%

      duware · dugalleryMay 11, 2006

    • CVE-2004-2201
      30Monitor

      SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID param

      HighCVSS 7.5Proof of conceptEPSS 1%

      duware · duforumDec 31, 2004

    • CVE-2005-3976
      30Monitor

      SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified

      HighCVSS 7.5No exploitEPSS 1%

      duware · duamazonDec 3, 2005

    • CVE-2005-2047
      30Monitor

      Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat

      HighCVSS 7.5No exploitEPSS 1%

      duware · dupaypal proJun 22, 2005

    • CVE-2008-2868
      30Monitor

      SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL com

      HighCVSS 7.5Proof of conceptEPSS 1%

      duware · ducalendarJun 26, 2008

    • CVE-2004-2198
      27Monitor

      account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_re

      MediumCVSS 6.4Proof of conceptEPSS 6%

      duware · duclassmateDec 31, 2004

    • CVE-2006-2132
      25Monitor

      SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter.

      MediumCVSS 6.4Proof of conceptEPSS 1%

      duware · duclassifiedMay 1, 2006

    • CVE-2006-4487
      20Monitor

      DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attac

      MediumCVSS 5.0No exploitEPSS 2%

      duware · dupollAug 31, 2006

    • CVE-2004-2200
      18Monitor

      Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML vi

      MediumCVSS 4.3No exploitEPSS 2%

      duware · duforumDec 31, 2004

    • CVE-2004-2199
      18Monitor

      Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the m

      MediumCVSS 4.3No exploitEPSS 2%

      duware · duclassifiedDec 31, 2004

    • CVE-2005-4166
      18Monitor

      Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script

      MediumCVSS 4.3Proof of conceptEPSS 2%

      duware · duportal proDec 11, 2005