Vulnerabilities (CVE)

Filtered by vendor Duware Subscribe
Total 23 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-2201 1 Duware 1 Duforum 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form.
CVE-2005-4166 1 Duware 1 Duportal Pro 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script or HTML via the result parameter.
CVE-2004-2198 1 Duware 1 Duclassmate 2025-04-03 6.4 MEDIUM N/A
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.