Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2006-6355
Disclosure Date: December 07, 2006 (last updated October 04, 2023)
SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parameter. NOTE: the iState parameter is already covered by CVE-2005-2049.
0
Attacker Value
Unknown
CVE-2005-2049
Disclosure Date: June 22, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro parameter to edit.asp.
0
Attacker Value
Unknown
CVE-2004-2198
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.
0