Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5) buyer.asp, or Keyword field in search.asp.
References
Configurations
History
20 Nov 2024, 23:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://echo.or.id/adv/adv21-theday-2005.txt - | |
References | () http://marc.info/?l=bugtraq&m=111963341429906&w=2 - | |
References | () http://www.securityfocus.com/bid/23110 - | |
References | () http://www.vupen.com/english/advisories/2007/1096 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/33183 - | |
References | () https://www.exploit-db.com/exploits/3550 - |
Information
Published : 2005-06-29 04:00
Updated : 2024-11-20 23:58
NVD link : CVE-2005-2062
Mitre link : CVE-2005-2062
CVE.ORG link : CVE-2005-2062
JSON object : View
Products Affected
active_web_softwares
- activebuyandsell
CWE