duware records
23 published records for vendor duware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 17
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2006-6355Proof of concept | SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parduware · duclassmate | Critical10.0 | — | 1.8% | Dec 6, 2006 |
31Monitor | CVE-2005-1224Proof of concept | Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChanduware · duportal | High7.5 | — | 3.7% | May 2, 2005 |
31Monitor | CVE-2005-2048Proof of concept | Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL cduware · duforum | High7.5 | — | 2.4% | Jun 22, 2005 |
31Monitor | CVE-2005-1236Proof of concept | Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via tduware · duportal | High7.5 | — | 2.4% | May 2, 2005 |
31Monitor | CVE-2005-2049Proof of concept | Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iStateduware · duclassmate | High7.5 | — | 2.4% | Jun 22, 2005 |
31Monitor | CVE-2005-2046Proof of concept | Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (duware · duamazon pro | High7.5 | — | 2.1% | Jun 22, 2005 |
31Monitor | CVE-2006-6354No exploit | Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) iduware · duamazon | High7.5 | — | 1.7% | Dec 6, 2006 |
30Monitor | CVE-2006-6367Proof of concept | Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitduware · dudownload · CWE-89 | High7.5 | — | 1.6% | Dec 7, 2006 |
30Monitor | CVE-2004-2202Proof of concept | Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute oduware · duclassified | High7.5 | — | 1.5% | Dec 31, 2004 |
30Monitor | CVE-2006-6365Proof of concept | SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL comduware · dupaypal | High7.5 | — | 1.4% | Dec 7, 2006 |
30Monitor | CVE-2005-2045No exploit | Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iChduware · duportal pro | High7.5 | — | 1.3% | Jun 22, 2005 |
30Monitor | CVE-2006-6455No exploit | Multiple SQL injection vulnerabilities in admin/default.asp in DUware DUdirectory 3.1, and possibly DUdirectory Pro and Pro SQL 3.x, allow rduware · dudirectory | High7.5 | — | 1.3% | Dec 10, 2006 |
30Monitor | CVE-2006-2302No exploit | SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Logiduware · dugallery | High7.5 | — | 1.3% | May 11, 2006 |
30Monitor | CVE-2004-2201Proof of concept | SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID paramduware · duforum | High7.5 | — | 1.3% | Dec 31, 2004 |
30Monitor | CVE-2005-3976No exploit | SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassifiedduware · duamazon | High7.5 | — | 1.2% | Dec 3, 2005 |
30Monitor | CVE-2005-2047No exploit | Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat duware · dupaypal pro | High7.5 | — | 1.2% | Jun 22, 2005 |
30Monitor | CVE-2008-2868Proof of concept | SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL comduware · ducalendar · CWE-89 | High7.5 | — | 1.2% | Jun 26, 2008 |
27Monitor | CVE-2004-2198Proof of concept | account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_reduware · duclassmate | Medium6.4 | — | 6.1% | Dec 31, 2004 |
25Monitor | CVE-2006-2132Proof of concept | SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter.duware · duclassified | Medium6.4 | — | 0.9% | May 1, 2006 |
20Monitor | CVE-2006-4487No exploit | DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attacduware · dupoll | Medium5.0 | — | 1.7% | Aug 31, 2006 |
18Monitor | CVE-2004-2200No exploit | Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML viduware · duforum | Medium4.3 | — | 1.9% | Dec 31, 2004 |
18Monitor | CVE-2004-2199No exploit | Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the mduware · duclassified | Medium4.3 | — | 1.9% | Dec 31, 2004 |
18Monitor | CVE-2005-4166Proof of concept | Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web scriptduware · duportal pro | Medium4.3 | — | 1.8% | Dec 11, 2005 |
- CVE-2006-635541Plan
SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity par
CriticalCVSS 10.0Proof of conceptEPSS 2%duware · duclassmateDec 6, 2006
- CVE-2005-122431Monitor
Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChan
HighCVSS 7.5Proof of conceptEPSS 4%duware · duportalMay 2, 2005
- CVE-2005-204831Monitor
Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL c
HighCVSS 7.5Proof of conceptEPSS 2%duware · duforumJun 22, 2005
- CVE-2005-123631Monitor
Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via t
HighCVSS 7.5Proof of conceptEPSS 2%duware · duportalMay 2, 2005
- CVE-2005-204931Monitor
Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState
HighCVSS 7.5Proof of conceptEPSS 2%duware · duclassmateJun 22, 2005
- CVE-2005-204631Monitor
Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (
HighCVSS 7.5Proof of conceptEPSS 2%duware · duamazon proJun 22, 2005
- CVE-2006-635431Monitor
Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) i
HighCVSS 7.5No exploitEPSS 2%duware · duamazonDec 6, 2006
- CVE-2006-636730Monitor
Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbit
HighCVSS 7.5Proof of conceptEPSS 2%duware · dudownloadDec 7, 2006
- CVE-2004-220230Monitor
Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute o
HighCVSS 7.5Proof of conceptEPSS 1%duware · duclassifiedDec 31, 2004
- CVE-2006-636530Monitor
SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL com
HighCVSS 7.5Proof of conceptEPSS 1%duware · dupaypalDec 7, 2006
- CVE-2005-204530Monitor
Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iCh
HighCVSS 7.5No exploitEPSS 1%duware · duportal proJun 22, 2005
- CVE-2006-645530Monitor
Multiple SQL injection vulnerabilities in admin/default.asp in DUware DUdirectory 3.1, and possibly DUdirectory Pro and Pro SQL 3.x, allow r
HighCVSS 7.5No exploitEPSS 1%duware · dudirectoryDec 10, 2006
- CVE-2006-230230Monitor
SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Logi
HighCVSS 7.5No exploitEPSS 1%duware · dugalleryMay 11, 2006
- CVE-2004-220130Monitor
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID param
HighCVSS 7.5Proof of conceptEPSS 1%duware · duforumDec 31, 2004
- CVE-2005-397630Monitor
SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified
HighCVSS 7.5No exploitEPSS 1%duware · duamazonDec 3, 2005
- CVE-2005-204730Monitor
Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat
HighCVSS 7.5No exploitEPSS 1%duware · dupaypal proJun 22, 2005
- CVE-2008-286830Monitor
SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL com
HighCVSS 7.5Proof of conceptEPSS 1%duware · ducalendarJun 26, 2008
- CVE-2004-219827Monitor
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_re
MediumCVSS 6.4Proof of conceptEPSS 6%duware · duclassmateDec 31, 2004
- CVE-2006-213225Monitor
SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter.
MediumCVSS 6.4Proof of conceptEPSS 1%duware · duclassifiedMay 1, 2006
- CVE-2006-448720Monitor
DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attac
MediumCVSS 5.0No exploitEPSS 2%duware · dupollAug 31, 2006
- CVE-2004-220018Monitor
Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML vi
MediumCVSS 4.3No exploitEPSS 2%duware · duforumDec 31, 2004
- CVE-2004-219918Monitor
Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the m
MediumCVSS 4.3No exploitEPSS 2%duware · duclassifiedDec 31, 2004
- CVE-2005-416618Monitor
Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script
MediumCVSS 4.3Proof of conceptEPSS 2%duware · duportal proDec 11, 2005