Multiple vulnerabilities have been identified in the software that may allow a remote attacker to carry out SQL injection and HTML injection attacks. An attacker may also gain unauthorized access to a user's account.
DUclassmate may allow unauthorized remote attackers to gain access to a computer.
DUclassified is reported prone to multiple SQL injection vulnerabilities.
SQL injection issues also affect DUforum.
DUclassified and DUforum are also reported vulnerable to various unspecified HTML injection vulnerabilities.
<input type="hidden" name="MM_recordId" value="[Your ID Number]">
DUclassmate contains a flaw in the 'account.asp' script that may lead to an unauthorized password exposure. It is possible to change other users passwords by altering the 'MM-recordId' value on the 'My Account' page, which may lead to a loss of integrity.
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.