CVE-2005-1029 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid (2) SortDir or (3) Sortby parameter to default.asp (4) itemID parameter to ItemInfo.asp or (5) Email field to sendpassword.asp.
Reference
http://digitalparadox.org/advisories/aass.txt http://marc.info/?l=bugtraq&m=111280834000432&w=2 http://secunia.com/advisories/14839 http://www.osvdb.org/15281 http://www.osvdb.org/15282 http://www.osvdb.org/15283 http://www.securityfocus.com/bid/13032 http://www.securityfocus.com/bid/13034 http://www.securityfocus.com/bid/13035 http://www.securitytracker.com/alerts/2005/Apr/1013649.html https://exchange.xforce.ibmcloud.com/vulnerabilities/19977
Share on: