peter bassill · operator
$ cve CVE-2005-2046 JSON

CVE-2005-2046 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.1% (pctl 81)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iSub parameter to sub.asp, (3) iSub parameter to detail.asp, (4) iPro parameter to review.asp, iCat parameter to (5) catEdit.asp, (6) catDelete.asp, (7) productEdit.asp, or (8) productDelete.asp, or (9) iType parameter to type.asp.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.08% — more likely to be exploited than 81% of all CVEs
On CISA KEVno
Public exploityes
Published2005-06-22
Last modified2026-06-16

Affected (1)

VendorProduct
duwareduamazon pro

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD