← Back

CVE-2006-6367

nvd nist
Published: Dec 7, 2006Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (2) action parameter. NOTE: the iType parameter is already covered by CVE-2005-3976.

Affected (8)

3 products
Dudownload
Dunews
Dupaypal
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Duware
Version 1.0
Version 1.1
Duware
Version 1.0
Version 1.1
Duware
Version 3.0
Version 3.1
Version pro_3.0
Version pro_3.1

References (12)

Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.