Vulnerabilities > CVE-2002-0995 - Unspecified vulnerability in Gianluca Baldo PHPauction
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN gianluca-baldo
exploit available
Summary
login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Exploit-Db
description | PHPAuction 1/2 Unauthorized Administrative Access Vulnerability. CVE-2002-0995. Webapps exploit for php platform |
id | EDB-ID:21590 |
last seen | 2016-02-02 |
modified | 2002-07-02 |
published | 2002-07-02 |
reporter | ethx |
source | https://www.exploit-db.com/download/21590/ |
title | PHPAuction 1/2 Unauthorized Administrative Access Vulnerability |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0014.html
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0014.html
- http://www.iss.net/security_center/static/9462.php
- http://www.iss.net/security_center/static/9462.php
- http://www.phpauction.org/viewnew.php?id=5
- http://www.phpauction.org/viewnew.php?id=5
- http://www.securityfocus.com/bid/5141
- http://www.securityfocus.com/bid/5141