Back

CVE-2005-3976

SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote attackers to execute arbitrary SQL commands via the iType parameter.

Published: Dec 3, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (11)

Vendor Product Version
duware duamazon 3.1
duware duarticle 1.1
duware duclassified 4.2
duware dudirectory 3.1
duware dudirectory_pro 3.0
duware dudirectory_pro_sql 3.0
duware dudownload 1.1
duware dugallery 3.3
duware dunews 1.1
duware dupaypal 3.1
duware dupaypal_pro 3.0

GitHub Security Advisory GHSA-8cpm-2q4p-34xp

SQL injection vulnerability in type.asp, as used in multiple DUware products including (1)...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.21%

Top 34% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub