Vulnerabilities > Phpauction

DATE CVE VULNERABILITY TITLE RISK
2009-08-19 CVE-2008-7000 Code Injection vulnerability in PHPauction 3.2
PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter.
network
low complexity
phpauction CWE-94
7.5
2009-08-19 CVE-2008-6999 Information Exposure vulnerability in PHPauction 3.2/3.3.0
phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
network
low complexity
phpauction CWE-200
5.0
2008-06-27 CVE-2008-2900 SQL Injection vulnerability in PHPauction 3.2
SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
phpauction CWE-89
7.5
2008-03-20 CVE-2008-1416 Code Injection vulnerability in PHPauction GPL 2.51
Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) converter.inc.php, (2) messages.inc.php, and (3) settings.inc.php in includes/.
network
phpauction CWE-94
6.8