Duware's vulnerability profile spans a modest portfolio of web application and directory-service products including DuClassified, DuPayPal, DuClassmate, DuDirectory, and DuDownload, each representing a point of potential exposure for organizations deploying this vendor's software. The most durable signal in this vendor's disclosures is the recurrence of SQL injection and related input-validation weaknesses, which are characteristic of web-facing application tiers where untrusted data flows directly into database queries. Notably, vulnerabilities affecting this vendor have frequently acquired public exploit code, making them attractive targets for routine scanning and mass-exploitation campaigns; organizations running these products should prioritize timely patching to reduce the window for weaponized access. The vendor's exposure is concentrated enough that defenders can track releases by product line, though the breadth of the affected application suite means vulnerabilities may propagate across multiple services within a single deployment. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Duware over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6355HIGH SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parameter. NOTE: the iState parameter is a | Dec 7, 2006 | 10.0 | 35 | NO | YES |
CVE-2004-2198MEDIUM account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" pag | Dec 31, 2004 | 6.4 | 33 | NO | YES |
CVE-2005-1224HIGH Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parameter to default.asp, cat.asp, o | May 2, 2005 | 7.5 | 29 | NO | YES |
CVE-2008-2868HIGH SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the iEve parameter. | Jun 26, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-6365HIGH SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: th | Dec 7, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6367HIGH Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or ( | Dec 7, 2006 | 7.5 | 28 | NO | YES |
CVE-2005-2046HIGH Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iSub p | Jun 22, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-2048HIGH Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) iMsg parameter to me | Jun 22, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-2049HIGH Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro pa | Jun 22, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-1236HIGH Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to channel.asp | May 2, 2005 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Duware.
Media articles that mention a CVE ID that affects a product developed by Duware — matched by CVE ID, not by vendor name.