VendorsGianluca Baldophpauction2.1
Vulnerabilities

Gianluca Baldo Phpauction 2.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2006-3984
PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNew 2.0.5, allows remote attackers to execute arbitrary PHP code via a URL in the phpAds_path parameter.
Published 2006-08-05 · Modified
7.51 PoCEPSS 0.032
CVE-2002-0995
login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table.
Published 2003-04-02 · Modified
7.51 PoCEPSS 0.028