Record summary

CVE-2004-2201 has a selected CVSS score of 7.5; EIP currently links 3 catalogued exploits.

Description

SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
3

Proofs of concept

3

Catalogued exploits

ExploitDBDUforum 3.x - Login Form 'Password' SQL InjectionExploitDB exploitby Soroosh DaliliNot analyzed1 file
ExploitDB

PoC details
ExploitDBDUforum 3.x - 'messages.asp?FOR_ID' SQL InjectionExploitDB exploitby Soroosh DaliliNot analyzed1 file
ExploitDB

PoC details
ExploitDBDUforum 3.x - 'messageDetail.asp?MSG_ID' SQL InjectionExploitDB exploitby Soroosh DaliliNot analyzed1 file
ExploitDB

PoC details

References

7