7.5
CVSSv2

CVE-2002-0995

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

login.php for PHPAuction allows remote malicious users to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table.

Vulnerable Product Search on Vulmon Subscribe to Product

gianluca baldo phpauction 1.2

gianluca baldo phpauction 1.3

gianluca baldo phpauction 2.0

gianluca baldo phpauction 2.1

Exploits

source: wwwsecurityfocuscom/bid/5141/info PhpAuction is a freely available web-based auction system It is written using PHP scripting language on a MySQL database engine A flaw in /admin/loginphp has been reported in PHPAuction, which could allow users to gain escalated privileges Submitting authentication credentials via loginphp ...