Back

CVE-2004-2201

SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
duware duforum 3.0
duware duforum 3.1

GitHub Security Advisory GHSA-mmhx-4q4c-qfq9

SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.29%

Top 32% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub