SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote attackers to execute arbitrary SQL commands via the iType parameter.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-12-03 11:03
Updated : 2017-07-19 18:29
NVD link : CVE-2005-3976
Mitre link : CVE-2005-3976
JSON object : View
CWE
Products Affected
duware
- dupaypal_pro
- duarticle
- dugallery
- dudirectory
- dunews
- dudirectory_pro_sql
- dupaypal
- dudownload
- dudirectory_pro
- duclassified
- duamazon