← Back

CVE-2006-6354

nvd nist
Published: Dec 7, 2006Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) iNews, (2) iType, or (3) Action parameter. NOTE: the iType parameter in type.asp is covered by CVE-2005-3976.

Affected (25)

11 products
Duamazon
Duarticle
Duclassified
Dudirectory
Dudirectory Pro
Dudirectory Pro Sql
Dudownload
Dugallery
Dunews
Dupaypal
Dupaypal Pro
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Duware
Version 3.0
Version 3.1
Duware
Version 1.0
Version 1.1
Duware
Version 4.0
Version 4.1
Version 4.2
Duware
Version 3.0
Version 3.1
Duware
Version 3.0
Version 3.1
Duware
Version 3.0
Version 3.1
Duware
Version 1.0
Version 1.1
Duware
Version 3.0
Version 3.1
Version 3.2
Version 3.3
Duware
Version 1.0
Version 1.1
Duware
Version 3.0
Version 3.1
Duware
Version 3.0
Version 3.1

References (14)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.