Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2005-2048

Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) iMsg parameter to messages.asp, iFor parameter to (2) post.asp or (3) forums.asp, or (4) id parameter to userEdit.asp. NOTE: vectors 1 and 3 were later reported to affect version 3.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.024
EPSS Ranking 82.5%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2005-2048


Contact Us

Shodan ® - All rights reserved