Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Active Auction House ItemInfo.ASP SQL注入漏洞
Vulnerability Description
Active Auction House是一款基于WEB的为拍卖行业务而设计的拍卖软件。 Active Auction House存在多个SQL注入漏洞,远程攻击者可以通过传递到default.asp的(1)catid,(2)SortDir或(3)Sortby参数,传到ItemInfo.asp的(4)itemID参数或传到sendpassword.asp的(5)Email字段来执行任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A