Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-4437. PoCs published by R3d-D3V!L.
AI-analyzed exploit summary This is a writeup describing a blind SQL injection vulnerability in Active Auction House v3.6. It provides example URLs for exploiting the vulnerability but does not include functional exploit code.
Description
Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to wishlist.asp and the (2) linkid parameter to links.asp. NOTE: vector 1 might overlap CVE-2005-1029.1.
Exploits (1)
This is a writeup describing a blind SQL injection vulnerability in Active Auction House v3.6. It provides example URLs for exploiting the vulnerability but does not include functional exploit code.