Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-2202. PoCs published by Soroosh Dalili.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in DUclassmate, DUclassified, and DUforum, including SQL injection and HTML injection. It includes an example URL demonstrating SQL injection but lacks executable exploit code.
Description
Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form.
Exploits (1)
The provided text describes multiple vulnerabilities in DUclassmate, DUclassified, and DUforum, including SQL injection and HTML injection. It includes an example URL demonstrating SQL injection but lacks executable exploit code.