CVE-2004-2202

DUware DUclassified <4.3 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Soroosh Dalili · textwebappsasp
https://www.exploit-db.com/exploits/24671

References (5)

Core 5
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11363
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17685
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/10669
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/10668
Exploit vdb-entry x_refsource_sectrack
http://www.securitytracker.com/alerts/2004/Oct/1011596.html

Scores

EPSS 0.0047
EPSS Percentile 64.7%

Details

Status published
Products (3)
duware/duclassified 4.0
duware/duclassified 4.1
duware/duclassified 4.2
Published Dec 31, 2004
Tracked Since Feb 18, 2026