VendorsActivewebsoftwaresactive_auction_houseall versions
Vulnerabilities

Activewebsoftwares Active Auction House

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2009-4437
Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to wishlist.asp and the (2) linkid parameter to links.asp. NOTE: vector 1 might overlap CVE-2005-1029.1.
Published 2009-12-28 · Modified
7.51 PoCEPSS 0.010