Duware
21 CVEs tracked since 2005. Since Apr 2005, none of them reached CISA KEV.
Duware CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2005-04 | 2 | 0 |
| 2005-05 | null or fewer | |
| 2005-06 | 5 | 0 |
| 2005-07 | 5 | 0 |
| 2005-08 | null or fewer | |
| 2005-09 | null or fewer | |
| 2005-10 | null or fewer | |
| 2005-11 | null or fewer | |
| 2005-12 | null or fewer | |
| 2006-01 | null or fewer | |
| 2006-02 | null or fewer | |
| 2006-03 | null or fewer | |
| 2006-04 | null or fewer | |
| 2006-05 | 2 | 0 |
| 2006-06 | null or fewer | |
| 2006-07 | null or fewer | |
| 2006-08 | 1 | 0 |
| 2006-09 | null or fewer | |
| 2006-10 | null or fewer | |
| 2006-11 | null or fewer | |
| 2006-12 | 5 | 0 |
| 2007-01 | null or fewer | |
| 2007-02 | null or fewer | |
| 2007-03 | null or fewer | |
| 2007-04 | null or fewer | |
| 2007-05 | null or fewer | |
| 2007-06 | null or fewer | |
| 2007-07 | null or fewer | |
| 2007-08 | null or fewer | |
| 2007-09 | null or fewer | |
| 2007-10 | null or fewer | |
| 2007-11 | null or fewer | |
| 2007-12 | null or fewer | |
| 2008-01 | null or fewer | |
| 2008-02 | null or fewer | |
| 2008-03 | null or fewer | |
| 2008-04 | null or fewer | |
| 2008-05 | null or fewer | |
| 2008-06 | 1 | 0 |
Products
The products that kept showing up in Duware's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Duware.
- CVE-2008-2868SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the iEve parameter.7.5
- CVE-2006-6455Multiple SQL injection vulnerabilities in admin/default.asp in DUware DUdirectory 3.1, and possibly DUdirectory Pro and Pro SQL 3.x, allow remote attackers to execute arbitrary SQL commands via the...7.5
- CVE-2006-6367Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (2) action paramet...7.5
- CVE-2006-6365SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: the iState paramete...7.5
- CVE-2006-6355SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parameter. NOTE: the iState parameter is already covered by...10.0
- CVE-2006-6354Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) iNews, (2) iType, or (3) Action parameter. NOTE: the iTyp...7.5
- CVE-2006-4487DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames an...5.0
- CVE-2006-2302SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password field.7.5
- CVE-2006-2132SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter. NOTE: the provenance of this information is unknown; the...6.4
- CVE-2005-3976SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0...7.5
- CVE-2004-2198account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.6.4
- CVE-2004-2202Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the...7.5
- CVE-2004-2200Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML via via the message text.4.3
- CVE-2004-2201SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDeta...7.5
- CVE-2004-2199Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the message text.4.3
The record
- Peak rank
- #17 in Jul 2005
- Busiest month shown
- Jun 2005, 5 CVEs
- Months with a KEV entry
- 0 since Apr 2005
- Monthly snapshots
- 7 since 2005