CVE Database
/

CVE-2004-2201

Back to search

CVE-2004-2201

Published: Jul 10, 2005

Modified: Aug 8, 2024

PUBLISHED

Description

SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form.

VendorProductVersions

n/a

n/a

affected
n/a

References

11363
vdb-entry
x_refsource_BID
1011595
vdb-entry
x_refsource_SECTRACK
10665
vdb-entry
x_refsource_OSVDB
10666
vdb-entry
x_refsource_OSVDB
10664
vdb-entry
x_refsource_OSVDB
duforum-sql-injection(17680)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now