CVE Tools

Duware

21 CVEs tracked since 2005. Since Apr 2005, none of them reached CISA KEV.

Duware CVEs per month

Apr 2005 to Jun 2008. Point at a month, or focus the strip and use the arrow keys.
Duware CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2005-0420
2005-05null or fewer
2005-0650
2005-0750
2005-08null or fewer
2005-09null or fewer
2005-10null or fewer
2005-11null or fewer
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-0520
2006-06null or fewer
2006-07null or fewer
2006-0810
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-1250
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-05null or fewer
2008-0610

Products

The products that kept showing up in Duware's monthly top three, with their CVEs summed over those months.

  1. Duclassified32 months
  2. Duforum32 months
  3. Dupaypal31 month
  4. Duclassmate22 months
  5. Dudirectory21 month
  6. Dunews21 month
  7. Duportal21 month
  8. Duamazon Pro11 month
  9. Ducalendar11 month
  10. Dugallery11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Duware.

  1. CVE-2008-2868SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the iEve parameter.7.5
  2. CVE-2006-6455Multiple SQL injection vulnerabilities in admin/default.asp in DUware DUdirectory 3.1, and possibly DUdirectory Pro and Pro SQL 3.x, allow remote attackers to execute arbitrary SQL commands via the...7.5
  3. CVE-2006-6367Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (2) action paramet...7.5
  4. CVE-2006-6365SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: the iState paramete...7.5
  5. CVE-2006-6355SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parameter. NOTE: the iState parameter is already covered by...10.0
  6. CVE-2006-6354Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) iNews, (2) iType, or (3) Action parameter. NOTE: the iTyp...7.5
  7. CVE-2006-4487DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames an...5.0
  8. CVE-2006-2302SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password field.7.5
  9. CVE-2006-2132SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter. NOTE: the provenance of this information is unknown; the...6.4
  10. CVE-2005-3976SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0...7.5
  11. CVE-2004-2198account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.6.4
  12. CVE-2004-2202Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the...7.5
  13. CVE-2004-2200Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML via via the message text.4.3
  14. CVE-2004-2201SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDeta...7.5
  15. CVE-2004-2199Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the message text.4.3

The record

Peak rank
#17 in Jul 2005
Busiest month shown
Jun 2005, 5 CVEs
Months with a KEV entry
0 since Apr 2005
Monthly snapshots
7 since 2005
Duware's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store