Gianluca Baldo
Gianluca Baldo Phpauction: vulnerabilidades y CVE
Gianluca Baldo Phpauction tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2006-3984 | Alta (7.5) | 3.2% | — | 5 ago 2006 | PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNew 2.0.5, allows remote attackers to execute arbitrary PHP code via a URL in the… |
| CVE-2005-2254 | Media (4.3) | 0.99% | — | 13 jul 2005 | Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to (1) index.php or (2) admin/index.php, or (3) the auction_id… |
| CVE-2005-2252 | Alta (7.5) | 1.4% | — | 13 jul 2005 | PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID. |
| CVE-2005-2253 | Alta (7.5) | 1.2% | — | 13 jul 2005 | SQL injection vulnerability in PhpAuction 2.5 allow remote attackers to modify SQL queries via the category parameter to adsearch.php. NOTE: there is evidence that viewnews.php may not be part of the PhpAuction product,… |
| CVE-2005-2255 | Media (6.4) | 1.5% | — | 13 jul 2005 | Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via ".." sequences in the lan parameter to (1) index.php… |
| CVE-2002-0995 | Alta (7.5) | 2.8% | — | 4 oct 2002 | login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table. |