CVE-2006-6367
Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (2) action parameter.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (2) action parameter. NOTE: the iType parameter is already covered by CVE-2005-3976.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.59% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- duware/dudownload · duware/dunews · duware/dupaypal
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=116508632603388&w=2Mailing List
- http://secunia.com/advisories/23224Vendor Advisory
- http://www.aria-security.com/forum/showthread.php?t=60Broken Link
- http://www.securityfocus.com/bid/21405Exploit, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/4845Not Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30669
- http://marc.info/?l=bugtraq&m=116508632603388&w=2Mailing List
- http://secunia.com/advisories/23224Vendor Advisory
- http://www.aria-security.com/forum/showthread.php?t=60Broken Link
- http://www.securityfocus.com/bid/21405Exploit, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/4845Not Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30669
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.