PT-2005-3182 · Phpauction · Phpauction
Published
2005-07-13
·
Updated
2008-09-05
·
CVE-2005-2253
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
PhpAuction version 2.5
Description:
The issue allows remote attackers to modify SQL queries. This is achieved via the
category parameter to the "adsearch.php" API endpoint.Recommendations:
For PhpAuction version 2.5, consider restricting access to the
adsearch.php endpoint until a patch is available, and avoid using the category parameter in this endpoint to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpauction