Vulnerabilities > CVE-2008-2279 - Credentials Management vulnerability in Freelance Auction Freelance Auction Script 1.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
freelance-auction
CWE-255
exploit available

Summary

Freelance Auction Script 1.0 stores user passwords in plaintext in the tbl_users table, which allows attackers to gain privileges by reading the table.

Vulnerable Configurations

Part Description Count
Application
Freelance_Auction
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionFreelance Auction Script 1.0 (browseproject.php) SQL Injection Vuln. CVE-2008-2278,CVE-2008-2279. Webapps exploit for php platform
fileexploits/php/webapps/5613.txt
idEDB-ID:5613
last seen2016-01-31
modified2008-05-14
platformphp
port
published2008-05-14
reportert0pP8uZz
sourcehttps://www.exploit-db.com/download/5613/
titleFreelance Auction Script 1.0 browseproject.php SQL Injection Vuln
typewebapps