HIGH · 7.5

CVE-2002-0995

login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table.

Vulnerability Description

login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Gianluca BaldoPhpauction1.2

References

FAQ

What is CVE-2002-0995?

CVE-2002-0995 is a vulnerability with a CVSS score of 7.5 (HIGH). login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table.

How severe is CVE-2002-0995?

CVE-2002-0995 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-0995?

Check the references section above for vendor advisories and patch information. Affected products include: Gianluca Baldo Phpauction.