CVE-2005-2062
ActiveBuyAndSell 6.2 - SQL Injection via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-2062. PoCs published by R3d-D3V!L, CyberGhost.
AI-analyzed exploit summary This is a writeup describing a blind SQL injection vulnerability in ActiveBuyandSell v6.2 via the 'catid' parameter in buyersend.asp. It provides example URLs for true and false conditions but does not include functional exploit code.
Description
Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5) buyer.asp, or Keyword field in search.asp.
Exploits (2)
This is a writeup describing a blind SQL injection vulnerability in ActiveBuyandSell v6.2 via the 'catid' parameter in buyersend.asp. It provides example URLs for true and false conditions but does not include functional exploit code.
This exploit demonstrates a SQL injection vulnerability in Active BuyandSell software, allowing an attacker to extract admin credentials via a crafted URL. The PoC provides specific paths to retrieve the admin username and password from the database.