CVE-2004-2202

Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:duware:duclassified:4.0:*:*:*:*:*:*:*
cpe:2.3:a:duware:duclassified:4.1:*:*:*:*:*:*:*
cpe:2.3:a:duware:duclassified:4.2:*:*:*:*:*:*:*

History

20 Nov 2024, 23:52

Type Values Removed Values Added
References () http://www.osvdb.org/10668 - Exploit () http://www.osvdb.org/10668 - Exploit
References () http://www.osvdb.org/10669 - Exploit () http://www.osvdb.org/10669 - Exploit
References () http://www.securityfocus.com/bid/11363 - Exploit () http://www.securityfocus.com/bid/11363 - Exploit
References () http://www.securitytracker.com/alerts/2004/Oct/1011596.html - Exploit () http://www.securitytracker.com/alerts/2004/Oct/1011596.html - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/17685 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/17685 -

Information

Published : 2004-12-31 05:00

Updated : 2024-11-20 23:52


NVD link : CVE-2004-2202

Mitre link : CVE-2004-2202

CVE.ORG link : CVE-2004-2202


JSON object : View

Products Affected

duware

  • duclassified