7.5
CVSSv2

CVE-2006-6367

Published: 07/12/2006 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote malicious users to execute arbitrary SQL commands via the (1) iFile or (2) action parameter. NOTE: the iType parameter is already covered by CVE-2005-3976.

Vulnerable Product Search on Vulmon Subscribe to Product

duware dunews 1.0

duware dunews 1.1

duware dudownload 1.0

duware dudownload 1.1

duware dupaypal 3.0

duware dupaypal 3.1

duware dupaypal pro_3.0

duware dupaypal pro_3.1

Exploits

source: wwwsecurityfocuscom/bid/21405/info Multiple DuWare products are prone to multiple SQL-injection vulnerabilities because they fail to properly sanitize user-supplied input before using it in SQL queries A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities i ...