Unrated severityNVD Advisory· Published Jun 22, 2005· Updated Apr 16, 2026
CVE-2005-2046
CVE-2005-2046
Description
Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iSub parameter to sub.asp, (3) iSub parameter to detail.asp, (4) iPro parameter to review.asp, iCat parameter to (5) catEdit.asp, (6) catDelete.asp, (7) productEdit.asp, or (8) productDelete.asp, or (9) iType parameter to type.asp.
Affected products
2cpe:2.3:a:duware:duamazon_pro:3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:duware:duamazon_pro:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:duware:duamazon_pro:3.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- echo.or.id/adv/adv19-theday-2005.txtnvdExploitVendor Advisory
- marc.infonvd
News mentions
0No linked articles in our index yet.