CVE-2005-1236

DUware DUportal 3.1.2 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2005-1236. PoCs published by Dcrab.

AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in DUportal/DUportal SQL 3.1.2 due to improper input sanitization. It includes an example URL demonstrating the vulnerability but lacks executable exploit code.

Description

Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to channel.asp or search.asp, (2) iData parameter to detail.asp or inc_rating.asp, (3) iCat parameter to detail.asp or type.asp, (4) DAT_PARENT parameter to inc_poll_voting.asp, or (5) iRate parameter to inc_rating.asp, a different set of vulnerabilities than CVE-2005-1224.

Exploits (4)

exploitdb WRITEUP VERIFIED
by Dcrab · textwebappsasp
https://www.exploit-db.com/exploits/25485

The provided text describes SQL injection vulnerabilities in DUportal/DUportal SQL 3.1.2 due to improper input sanitization. It includes an example URL demonstrating the vulnerability but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: DUportal/DUportal SQL 3.1.2
No auth needed
Prerequisites: Access to the vulnerable application URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Dcrab · textwebappsasp
https://www.exploit-db.com/exploits/25484

The provided text describes SQL injection vulnerabilities in DUportal/DUportal SQL, specifically in the 'inc_rating.asp' file. It includes example URLs demonstrating how unsanitized input can be exploited but does not contain executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: DUportal/DUportal SQL 3.1.2
No auth needed
Prerequisites: Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Dcrab · textwebappsasp
https://www.exploit-db.com/exploits/25483

The provided text describes SQL injection vulnerabilities in DUportal/DUportal SQL due to improper input sanitization. It includes a sample exploit URL demonstrating the vulnerability but lacks executable code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: DUportal/DUportal SQL 3.1.2
No auth needed
Prerequisites: Access to the vulnerable URL parameter
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Dcrab · textwebappsasp
https://www.exploit-db.com/exploits/25482

The provided text describes SQL injection vulnerabilities in DUportal/DUportal SQL 3.1.2 due to improper input sanitization. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: DUportal/DUportal SQL 3.1.2
No auth needed
Prerequisites: Access to the vulnerable application URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15044
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13288

Scores

EPSS 0.0241
EPSS Percentile 82.0%

Details

Status published
Products (2)
duware/duportal 3.1.2
duware/duportal 3.1.2_sql
Published May 02, 2005
Tracked Since Feb 18, 2026