Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5) buyer.asp, or Keyword field in search.asp.
References
Configurations
Information
Published : 2005-06-28 21:00
Updated : 2017-10-10 18:30
NVD link : CVE-2005-2062
Mitre link : CVE-2005-2062
JSON object : View
CWE
Products Affected
active_web_softwares
- activebuyandsell


