« Volver al listado

CVE-2002-0995

Estado: ModificadaAlta (7.5)—

login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2002-0995",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2002-10-04T04:00:00.000",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2002-07/0014.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.iss.net/security_center/static/9462.php",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.phpauction.org/viewnew.php?id=5",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/5141",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2002-07/0014.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.iss.net/security_center/static/9462.php",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.phpauction.org/viewnew.php?id=5",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/5141",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to \"insert,\" which adds the provided username to the adminUsers table."
    }
  ],
  "lastModified": "2026-06-16T21:58:31.970",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gianluca_baldo:phpauction:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21DEE163-5D84-4B74-807D-D0155D4D91F8"
            },
            {
              "criteria": "cpe:2.3:a:gianluca_baldo:phpauction:1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2332338A-753D-4B34-95E3-B205F290895E"
            },
            {
              "criteria": "cpe:2.3:a:gianluca_baldo:phpauction:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1044F5A0-FEA0-46D4-8E98-6E915CA398DD"
            },
            {
              "criteria": "cpe:2.3:a:gianluca_baldo:phpauction:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "834E6244-8A54-4D49-833E-C49D047D93E2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}