SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote attackers to execute arbitrary SQL commands via the iType parameter.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/17835 - Vendor Advisory | |
References | () http://www.osvdb.org/21385 - | |
References | () http://www.securityfocus.com/bid/15681 - | |
References | () http://www.vupen.com/english/advisories/2005/2700 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/30673 - |
Information
Published : 2005-12-03 19:03
Updated : 2024-11-21 00:03
NVD link : CVE-2005-3976
Mitre link : CVE-2005-3976
CVE.ORG link : CVE-2005-3976
JSON object : View
Products Affected
duware
- dudirectory_pro
- dudownload
- dupaypal_pro
- dudirectory_pro_sql
- dunews
- duclassified
- duarticle
- dupaypal
- duamazon
- dudirectory
- dugallery
CWE