PT-2002-2001 · Phpauction · Phpauction

Published

2002-10-04

·

Updated

2008-09-05

·

CVE-2002-0995

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PHPAuction (affected versions not specified)
Description: The issue allows remote attackers to gain privileges by making a direct call to "login.php" with the action parameter set to "insert". This action adds the provided username to the adminUsers table.
Recommendations: For PHPAuction, to mitigate this issue, consider restricting access to the "login.php" endpoint, specifically when the action parameter is set to "insert", until a proper fix is implemented. As a temporary workaround, disabling the ability to add users to the adminUsers table via the "login.php" endpoint can help minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0995

Affected Products

Phpauction