CVE-2005-2046 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.1% (pctl 81)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iSub parameter to sub.asp, (3) iSub parameter to detail.asp, (4) iPro parameter to review.asp, iCat parameter to (5) catEdit.asp, (6) catDelete.asp, (7) productEdit.asp, or (8) productDelete.asp, or (9) iType parameter to type.asp.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.08% — more likely to be exploited than 81% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-06-22 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| duware | duamazon pro |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | DUware DUamazon Pro 3.0/3.1 - 'type.asp?iType' SQL Injection | 2005-06-22 |
| exploit-db | DUware DUamazon Pro 3.0/3.1 - 'productDelete.asp?iCat' SQL Injection | 2005-06-22 |
| exploit-db | DUware DUamazon Pro 3.0/3.1 - 'productEdit.asp?iCat' SQL Injection | 2005-06-22 |
| exploit-db | DUware DUamazon Pro 3.0/3.1 - 'catDelete.asp?iCat' SQL Injection | 2005-06-22 |
| exploit-db | DUware DUamazon Pro 3.0/3.1 - 'review.asp?iPro' SQL Injection | 2005-06-22 |
| exploit-db | DUware DUamazon Pro 3.0/3.1 - 'detail.asp?iSub' SQL Injection | 2005-06-22 |
| exploit-db | DUware DUpaypal 3.0/3.1 - 'sub.asp?iSub' SQL Injection | 2005-06-22 |
References
→ the Explorer · watch your stack · NVD