|
|
>> DUware Multiple Products "iType" Remote SQL Injection Vulnerability
|
Title : DUware Multiple Products "iType" Remote SQL Injection Vulnerability VUPEN ID : VUPEN/ADV-2005-2700 CVE ID : CVE-2005-3976
Rated as : Moderate Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-02
|
|
A vulnerability has been identified in multiple DUware products, which may be exploited by remote attackers to execute arbitrary SQL commands [...]
Affected Products
DUamazon version 3.1 and prior
DUarticle version 1.1 and prior
DUclassified version 4.2 and prior
DUdirectory version 3.1 and prior
DUdirectory Pro version 3.0 and prior
DUdirectory Pro version 3.0 SQL and prior
DUdownload version 1.1 and prior
DUgallery version 3.3 and prior
DUnews version 1.1 and prior
DUpaypal version 3.1 and prior
DUpaypal version Pro 3.0 and prior
Credits
Vulnerability reported by syst3m f4ult
ChangeLog
2005-12-02 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|