CVE-2009-0429

Active Bids - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to search.asp, (2) SortDir parameter to auctionsended.asp, and the (3) catid parameter to wishlist.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Pouya_Server · textwebappsasp
https://www.exploit-db.com/exploits/32731

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/500144/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33306

Scores

EPSS 0.0038
EPSS Percentile 59.5%

Details

CWE
CWE-89
Status published
Products (1)
activewebsoftwares/active_bids
Published Feb 05, 2009
Tracked Since Feb 18, 2026