Security Advisory

CVE-2002-0995

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2003-04-02 05:00:00
Last updated 2024-08-08 03:12:16
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table.