PT-2009-6558 · Unknown · Active Auction House

R3D-D3V!L

·

Published

2009-12-28

·

Updated

2017-08-17

·

CVE-2009-4437

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Active Auction House version 3.6
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the catid parameter to "wishlist.asp" and the linkid parameter to "links.asp".
Recommendations For Active Auction House version 3.6, consider restricting access to the wishlist.asp and links.asp pages until a fix is available, and avoid using the catid and linkid parameters in these pages to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4437

Affected Products

Active Auction House