Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2006-6355

Disclosure Date: December 07, 2006 (last updated October 04, 2023)
SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parameter. NOTE: the iState parameter is already covered by CVE-2005-2049.
0
Attacker Value
Unknown

CVE-2005-2049

Disclosure Date: June 22, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro parameter to edit.asp.
0
Attacker Value
Unknown

CVE-2004-2198

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.
0