SQL injection vulnerability in default.asp in Active Trade 2 allows remote malicious users to execute arbitrary SQL commands via the catid parameter.
active trade active trade 2