Записи duware
23 опубликованных записей вендора duware.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 17
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
23 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2006-6355Proof of concept | SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parduware · duclassmate | Критическая10,0 | — | 1,8 % | 6 дек. 2006 г. |
31Наблюдать | CVE-2005-1224Proof of concept | Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChanduware · duportal | Высокая7,5 | — | 3,7 % | 2 мая 2005 г. |
31Наблюдать | CVE-2005-2048Proof of concept | Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL cduware · duforum | Высокая7,5 | — | 2,4 % | 22 июн. 2005 г. |
31Наблюдать | CVE-2005-1236Proof of concept | Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via tduware · duportal | Высокая7,5 | — | 2,4 % | 2 мая 2005 г. |
31Наблюдать | CVE-2005-2049Proof of concept | Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iStateduware · duclassmate | Высокая7,5 | — | 2,4 % | 22 июн. 2005 г. |
31Наблюдать | CVE-2005-2046Proof of concept | Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (duware · duamazon pro | Высокая7,5 | — | 2,1 % | 22 июн. 2005 г. |
31Наблюдать | CVE-2006-6354Эксплойта нет | Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) iduware · duamazon | Высокая7,5 | — | 1,7 % | 6 дек. 2006 г. |
30Наблюдать | CVE-2006-6367Proof of concept | Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitduware · dudownload · CWE-89 | Высокая7,5 | — | 1,6 % | 7 дек. 2006 г. |
30Наблюдать | CVE-2004-2202Proof of concept | Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute oduware · duclassified | Высокая7,5 | — | 1,5 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2006-6365Proof of concept | SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL comduware · dupaypal | Высокая7,5 | — | 1,4 % | 7 дек. 2006 г. |
30Наблюдать | CVE-2005-2045Эксплойта нет | Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iChduware · duportal pro | Высокая7,5 | — | 1,3 % | 22 июн. 2005 г. |
30Наблюдать | CVE-2006-6455Эксплойта нет | Multiple SQL injection vulnerabilities in admin/default.asp in DUware DUdirectory 3.1, and possibly DUdirectory Pro and Pro SQL 3.x, allow rduware · dudirectory | Высокая7,5 | — | 1,3 % | 10 дек. 2006 г. |
30Наблюдать | CVE-2006-2302Эксплойта нет | SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Logiduware · dugallery | Высокая7,5 | — | 1,3 % | 11 мая 2006 г. |
30Наблюдать | CVE-2004-2201Proof of concept | SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID paramduware · duforum | Высокая7,5 | — | 1,3 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2005-3976Эксплойта нет | SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassifiedduware · duamazon | Высокая7,5 | — | 1,2 % | 3 дек. 2005 г. |
30Наблюдать | CVE-2005-2047Эксплойта нет | Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat duware · dupaypal pro | Высокая7,5 | — | 1,2 % | 22 июн. 2005 г. |
30Наблюдать | CVE-2008-2868Proof of concept | SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL comduware · ducalendar · CWE-89 | Высокая7,5 | — | 1,2 % | 26 июн. 2008 г. |
27Наблюдать | CVE-2004-2198Proof of concept | account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_reduware · duclassmate | Средняя6,4 | — | 6,1 % | 31 дек. 2004 г. |
25Наблюдать | CVE-2006-2132Proof of concept | SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter.duware · duclassified | Средняя6,4 | — | 0,9 % | 1 мая 2006 г. |
20Наблюдать | CVE-2006-4487Эксплойта нет | DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attacduware · dupoll | Средняя5,0 | — | 1,7 % | 31 авг. 2006 г. |
18Наблюдать | CVE-2004-2200Эксплойта нет | Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML viduware · duforum | Средняя4,3 | — | 1,9 % | 31 дек. 2004 г. |
18Наблюдать | CVE-2004-2199Эксплойта нет | Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the mduware · duclassified | Средняя4,3 | — | 1,9 % | 31 дек. 2004 г. |
18Наблюдать | CVE-2005-4166Proof of concept | Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web scriptduware · duportal pro | Средняя4,3 | — | 1,8 % | 11 дек. 2005 г. |
- CVE-2006-635541В плане
SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity par
КритическаяCVSS 10,0Proof of conceptEPSS 2 %duware · duclassmate6 дек. 2006 г.
- CVE-2005-122431Наблюдать
Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChan
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %duware · duportal2 мая 2005 г.
- CVE-2005-204831Наблюдать
Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL c
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %duware · duforum22 июн. 2005 г.
- CVE-2005-123631Наблюдать
Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via t
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %duware · duportal2 мая 2005 г.
- CVE-2005-204931Наблюдать
Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %duware · duclassmate22 июн. 2005 г.
- CVE-2005-204631Наблюдать
Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %duware · duamazon pro22 июн. 2005 г.
- CVE-2006-635431Наблюдать
Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) i
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %duware · duamazon6 дек. 2006 г.
- CVE-2006-636730Наблюдать
Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbit
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %duware · dudownload7 дек. 2006 г.
- CVE-2004-220230Наблюдать
Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute o
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %duware · duclassified31 дек. 2004 г.
- CVE-2006-636530Наблюдать
SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL com
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %duware · dupaypal7 дек. 2006 г.
- CVE-2005-204530Наблюдать
Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iCh
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %duware · duportal pro22 июн. 2005 г.
- CVE-2006-645530Наблюдать
Multiple SQL injection vulnerabilities in admin/default.asp in DUware DUdirectory 3.1, and possibly DUdirectory Pro and Pro SQL 3.x, allow r
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %duware · dudirectory10 дек. 2006 г.
- CVE-2006-230230Наблюдать
SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Logi
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %duware · dugallery11 мая 2006 г.
- CVE-2004-220130Наблюдать
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID param
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %duware · duforum31 дек. 2004 г.
- CVE-2005-397630Наблюдать
SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %duware · duamazon3 дек. 2005 г.
- CVE-2005-204730Наблюдать
Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %duware · dupaypal pro22 июн. 2005 г.
- CVE-2008-286830Наблюдать
SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL com
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %duware · ducalendar26 июн. 2008 г.
- CVE-2004-219827Наблюдать
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_re
СредняяCVSS 6,4Proof of conceptEPSS 6 %duware · duclassmate31 дек. 2004 г.
- CVE-2006-213225Наблюдать
SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter.
СредняяCVSS 6,4Proof of conceptEPSS 1 %duware · duclassified1 мая 2006 г.
- CVE-2006-448720Наблюдать
DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attac
СредняяCVSS 5,0Эксплойта нетEPSS 2 %duware · dupoll31 авг. 2006 г.
- CVE-2004-220018Наблюдать
Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML vi
СредняяCVSS 4,3Эксплойта нетEPSS 2 %duware · duforum31 дек. 2004 г.
- CVE-2004-219918Наблюдать
Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the m
СредняяCVSS 4,3Эксплойта нетEPSS 2 %duware · duclassified31 дек. 2004 г.
- CVE-2005-416618Наблюдать
Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script
СредняяCVSS 4,3Proof of conceptEPSS 2 %duware · duportal pro11 дек. 2005 г.