CVE-2004-2202

DUware DUclassified <4.3 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-2202. PoCs published by Soroosh Dalili.

AI-analyzed exploit summary The provided text describes multiple vulnerabilities in DUclassmate, DUclassified, and DUforum, including SQL injection and HTML injection. It includes an example URL demonstrating SQL injection but lacks executable exploit code.

Description

Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Soroosh Dalili · textwebappsasp
https://www.exploit-db.com/exploits/24671

The provided text describes multiple vulnerabilities in DUclassmate, DUclassified, and DUforum, including SQL injection and HTML injection. It includes an example URL demonstrating SQL injection but lacks executable exploit code.

Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: DUclassmate, DUclassified, DUforum
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11363
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17685
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/10669
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/10668
Exploit vdb-entry x_refsource_sectrack
http://www.securitytracker.com/alerts/2004/Oct/1011596.html

Scores

EPSS 0.0145
EPSS Percentile 70.1%

Details

Status published
Products (3)
duware/duclassified 4.0
duware/duclassified 4.1
duware/duclassified 4.2
Published Dec 31, 2004
Tracked Since Feb 18, 2026