peter bassill · operator
$ cve CVE-2005-2049 JSON

CVE-2005-2049 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 84)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro parameter to edit.asp.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.41% — more likely to be exploited than 84% of all CVEs
On CISA KEVno
Public exploityes
Published2005-06-22
Last modified2026-06-16

Affected (1)

VendorProduct
duwareduclassmate

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD