VendorsActive Web Softwaresactive_auction_house7.1
Vulnerabilities

Active Web Softwares Active Auction House 7.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2005-1029
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp.
Published 2005-04-09 · Modified
7.52 PoCEPSS 0.043
CVE-2007-1712
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Auction Pro 7.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
Published 2007-03-27 · Modified
7.51 PoCEPSS 0.010
CVE-2005-1030
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1) ReturnURL, (2) password, (3) username parameter, (4) ReturnURL parameter to account.asp, (5) Table, (6) Title parameter to sendpassword.asp, or (7) itemid to watchthisitem.asp.
Published 2005-04-09 · Modified
4.34 PoCEPSS 0.051