Show filters
23 Total Results
Displaying 21-23 of 23
Sort by:
Attacker Value
Unknown
CVE-2004-2202
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form.
0
Attacker Value
Unknown
CVE-2004-2201
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form.
0
Attacker Value
Unknown
CVE-2004-2199
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the message text.
0