PT-2008-2997 · Phpauction · Phpauction Gpl

Romancyxhacker

·

Published

2008-03-20

·

Updated

2017-09-29

·

CVE-2008-1416

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHPauction GPL version 2.51
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the include path parameter to specific PHP files, including (1) converter.inc.php, (2) messages.inc.php, and (3) settings.inc.php in the includes/ directory.
Recommendations For PHPauction GPL version 2.51, consider restricting access to the vulnerable PHP files, specifically converter.inc.php, messages.inc.php, and settings.inc.php, until a patch is available. As a temporary workaround, avoid using the include path parameter in these files to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1416

Affected Products

Phpauction Gpl