7.5
CVE-2005-2046
- EPSS 2.08%
- Veröffentlicht 22.06.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:14:08
- Erkennungen
Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iSub parameter to sub.asp, (3) iSub parameter to detail.asp, (4) iPro parameter to review.asp, iCat parameter to (5) catEdit.asp, (6) catDelete.asp, (7) productEdit.asp, or (8) productDelete.asp, or (9) iType parameter to type.asp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Duware ≫ Duamazon Pro Version 3.0
Duware ≫ Duamazon Pro Version 3.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.08% | 0.791 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://echo.or.id/adv/adv19-theday-2005.txt
http://marc.info/?l=bugtraq&m=111945219205114&w=2