SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote attackers to execute arbitrary SQL commands via the iType parameter.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2005-12-03 19:03
Updated : 2024-02-28 10:42
NVD link : CVE-2005-3976
Mitre link : CVE-2005-3976
CVE.ORG link : CVE-2005-3976
JSON object : View
Products Affected
duware
- duamazon
- dudirectory
- dugallery
- dunews
- dudownload
- duarticle
- dudirectory_pro
- dudirectory_pro_sql
- dupaypal_pro
- dupaypal
- duclassified
CWE