10664vdb entry
http://www.osvdb.org/10664 CVE-2004-2201
DUforum 3.x - Login Form 'Password' SQL Injection
Record summary
CVE-2004-2201 has a selected CVSS score of 7.5; EIP currently links 3 catalogued exploits.
Description
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBDUforum 3.x - Login Form 'Password' SQL InjectionExploitDB exploitby Soroosh DaliliNot analyzed1 file
ExploitDBDUforum 3.x - 'messages.asp?FOR_ID' SQL InjectionExploitDB exploitby Soroosh DaliliNot analyzed1 file
ExploitDBDUforum 3.x - 'messageDetail.asp?MSG_ID' SQL InjectionExploitDB exploitby Soroosh DaliliNot analyzed1 file
References
710665vdb entry
http://www.osvdb.org/10665 10666vdb entry
http://www.osvdb.org/10666 11363vdb entry
http://www.securityfocus.com/bid/11363 1011595vdb entry
http://www.securitytracker.com/alerts/2004/Oct/1011595.html duforum-sql-injection(17680)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17680 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2201