Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) iMsg parameter to messages.asp, iFor parameter to (2) post.asp or (3) forums.asp, or (4) id parameter to userEdit.asp. NOTE: vectors 1 and 3 were later reported to affect version 3.0.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2005-06-22T04:00:00
Updated: 2018-10-19T14:57:01
Reserved: 2005-06-22T00:00:00
Link: CVE-2005-2048
JSON object: View
NVD Information
Status : Modified
Published: 2005-06-22T04:00:00.000
Modified: 2018-10-19T15:32:11.690
Link: CVE-2005-2048
JSON object: View
Redhat Information
No data.
CWE