Vulnerabilities > CVE-2005-2049 - SQL Injection vulnerability in Duware Duclassmate 1.2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro parameter to edit.asp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description DUware DUclassmate 1.x default.asp iState Parameter SQL Injection. CVE-2005-2049. Webapps exploit for asp platform id EDB-ID:25872 last seen 2016-02-03 modified 2005-06-01 published 2005-06-01 reporter Dedi Dwianto source https://www.exploit-db.com/download/25872/ title DUware DUclassmate 1.x default.asp iState Parameter SQL Injection description DUware DUclassmate 1.x edit.asp iPro Parameter SQL Injection. CVE-2005-2049 . Webapps exploit for asp platform id EDB-ID:25873 last seen 2016-02-03 modified 2005-06-01 published 2005-06-01 reporter Dedi Dwianto source https://www.exploit-db.com/download/25873/ title DUware DUclassmate 1.x edit.asp iPro Parameter SQL Injection
Nessus
NASL family | CGI abuses |
NASL id | DUCLASSMATE_SQL_INJECTIONS.NASL |
description | The remote host is running DUclassmate, a web-based classmates listing and friends search application from DUware and written in ASP. The installed version of DUclassmate fails to properly sanitize user- supplied input in several instances before using it in SQL queries. By exploiting these flaws, an attacker can affect database queries, possibly disclosing sensitive data and launching attacks against the underlying database. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18566 |
published | 2005-06-28 |
reporter | This script is Copyright (C) 2005-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/18566 |
title | DUclassmate Multiple Scripts SQL Injection |