Перейти к содержимому
Noroxi

Записи duware

23 опубликованных записей вендора duware.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
17
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

    Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

    CWE

    Все записи

    23 записей
    • CVE-2006-6355
      41В плане

      SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity par

      КритическаяCVSS 10,0Proof of conceptEPSS 2 %

      duware · duclassmate6 дек. 2006 г.

    • CVE-2005-1224
      31Наблюдать

      Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChan

      ВысокаяCVSS 7,5Proof of conceptEPSS 4 %

      duware · duportal2 мая 2005 г.

    • CVE-2005-2048
      31Наблюдать

      Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL c

      ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

      duware · duforum22 июн. 2005 г.

    • CVE-2005-1236
      31Наблюдать

      Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via t

      ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

      duware · duportal2 мая 2005 г.

    • CVE-2005-2049
      31Наблюдать

      Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState

      ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

      duware · duclassmate22 июн. 2005 г.

    • CVE-2005-2046
      31Наблюдать

      Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (

      ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

      duware · duamazon pro22 июн. 2005 г.

    • CVE-2006-6354
      31Наблюдать

      Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) i

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      duware · duamazon6 дек. 2006 г.

    • CVE-2006-6367
      30Наблюдать

      Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbit

      ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

      duware · dudownload7 дек. 2006 г.

    • CVE-2004-2202
      30Наблюдать

      Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute o

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      duware · duclassified31 дек. 2004 г.

    • CVE-2006-6365
      30Наблюдать

      SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL com

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      duware · dupaypal7 дек. 2006 г.

    • CVE-2005-2045
      30Наблюдать

      Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iCh

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      duware · duportal pro22 июн. 2005 г.

    • CVE-2006-6455
      30Наблюдать

      Multiple SQL injection vulnerabilities in admin/default.asp in DUware DUdirectory 3.1, and possibly DUdirectory Pro and Pro SQL 3.x, allow r

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      duware · dudirectory10 дек. 2006 г.

    • CVE-2006-2302
      30Наблюдать

      SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Logi

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      duware · dugallery11 мая 2006 г.

    • CVE-2004-2201
      30Наблюдать

      SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID param

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      duware · duforum31 дек. 2004 г.

    • CVE-2005-3976
      30Наблюдать

      SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      duware · duamazon3 дек. 2005 г.

    • CVE-2005-2047
      30Наблюдать

      Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      duware · dupaypal pro22 июн. 2005 г.

    • CVE-2008-2868
      30Наблюдать

      SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL com

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      duware · ducalendar26 июн. 2008 г.

    • CVE-2004-2198
      27Наблюдать

      account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_re

      СредняяCVSS 6,4Proof of conceptEPSS 6 %

      duware · duclassmate31 дек. 2004 г.

    • CVE-2006-2132
      25Наблюдать

      SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter.

      СредняяCVSS 6,4Proof of conceptEPSS 1 %

      duware · duclassified1 мая 2006 г.

    • CVE-2006-4487
      20Наблюдать

      DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attac

      СредняяCVSS 5,0Эксплойта нетEPSS 2 %

      duware · dupoll31 авг. 2006 г.

    • CVE-2004-2200
      18Наблюдать

      Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML vi

      СредняяCVSS 4,3Эксплойта нетEPSS 2 %

      duware · duforum31 дек. 2004 г.

    • CVE-2004-2199
      18Наблюдать

      Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the m

      СредняяCVSS 4,3Эксплойта нетEPSS 2 %

      duware · duclassified31 дек. 2004 г.

    • CVE-2005-4166
      18Наблюдать

      Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script

      СредняяCVSS 4,3Proof of conceptEPSS 2 %

      duware · duportal pro11 дек. 2005 г.