RSS   Vulnerabilities for 'Active auction house'   RSS

2009-12-28
 
CVE-2009-4437

CWE-89
 

 
Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to wishlist.asp and the (2) linkid parameter to links.asp. NOTE: vector 1 might overlap CVE-2005-1029.1.

 

 >>> Vendor: Activewebsoftwares 18 Products
Activevotes
Active trade
Active ewebquiz
Active time billing
Active force matrix
Active membership
Active price comparison
Active bids
Active photo gallery
Active test
Active business directory
Active web mail
Active newsletter
Active web helpdesk
Quick tree view .net
Aspreferral
Ewebquiz
Active auction house


Copyright 2019, cxsecurity.com

 

Back to Top