Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iSub parameter to sub.asp, (3) iSub parameter to detail.asp, (4) iPro parameter to review.asp, iCat parameter to (5) catEdit.asp, (6) catDelete.asp, (7) productEdit.asp, or (8) productDelete.asp, or (9) iType parameter to type.asp.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2005-06-22T04:00:00
Updated: 2024-08-07T22:15:36.831Z
Reserved: 2005-06-22T00:00:00
Link: CVE-2005-2046

No data.

Status : Deferred
Published: 2005-06-22T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-2046

No data.