CVE-2009-0429
Active Bids - SQL Injection via search.asp search Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0429. PoCs published by Pouya_Server.
AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in Active Auction House and Active Auction Pro due to insufficient input sanitization. It includes a sample exploit URL for SQL injection but lacks executable code.
Description
Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to search.asp, (2) SortDir parameter to auctionsended.asp, and the (3) catid parameter to wishlist.php.
Exploits (1)
The provided text describes SQL injection and XSS vulnerabilities in Active Auction House and Active Auction Pro due to insufficient input sanitization. It includes a sample exploit URL for SQL injection but lacks executable code.