Lucene search

K
cveMitreCVE-2005-1236
HistoryMay 02, 2005 - 4:00 a.m.

CVE-2005-1236

2005-05-0204:00:00
mitre
web.nvd.nist.gov
22
cve-2005-1236
sql injection
duware duportal
remote attackers
arbitrary sql commands

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.5

Confidence

Low

EPSS

0.006

Percentile

79.2%

Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to channel.asp or search.asp, (2) iData parameter to detail.asp or inc_rating.asp, (3) iCat parameter to detail.asp or type.asp, (4) DAT_PARENT parameter to inc_poll_voting.asp, or (5) iRate parameter to inc_rating.asp, a different set of vulnerabilities than CVE-2005-1224.

Affected configurations

Nvd
Node
duwareduportalMatch3.1.2
OR
duwareduportalMatch3.1.2_sql
VendorProductVersionCPE
duwareduportal3.1.2cpe:2.3:a:duware:duportal:3.1.2:*:*:*:*:*:*:*
duwareduportal3.1.2_sqlcpe:2.3:a:duware:duportal:3.1.2_sql:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.5

Confidence

Low

EPSS

0.006

Percentile

79.2%

Related for CVE-2005-1236