Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2005-2045
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-2045

Description:
Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to default.asp, (2) iData parameter to detail.asp, (3) iMem parameter to members.asp, (4) iCat parameter to cat.asp, (5) offset parameter to members_listing_approval.asp, or (6) iChannel parameter to channels_edit.asp.

CVE Status:
Candidate

References:

OSVDB
  17598
  17599
  17597

MISC
  http://echo.or.id/adv/adv19-theday-2005.txt

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=111945219205114&w=2


Return to the previous page.