7.5
CVSSv2

CVE-2006-6354

Published: 07/12/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote malicious users to execute arbitrary SQL commands via the (1) iNews, (2) iType, or (3) Action parameter. NOTE: the iType parameter in type.asp is covered by CVE-2005-3976.

Vulnerable Product Search on Vulmon Subscribe to Product

duware duclassified 4.1

duware duclassified 4.2

duware dudownload 1.0

duware dudownload 1.1

duware dupaypal 3.0

duware dupaypal 3.1

duware duamazon 3.0

duware duamazon 3.1

duware dudirectory pro 3.0

duware dudirectory pro 3.1

duware dugallery 3.2

duware dugallery 3.3

duware dudirectory 3.0

duware dudirectory 3.1

duware dugallery 3.0

duware dugallery 3.1

duware dupaypal pro 3.0

duware dupaypal pro 3.1

duware duarticle 1.0

duware duarticle 1.1

duware duclassified 4.0

duware dudirectory pro sql 3.0

duware dudirectory pro sql 3.1

duware dunews 1.0

duware dunews 1.1