CVE-2002-0995

Publication date

2003-04-02 05:00:00

Family

mitre

State

PUBLISHED

Description

login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table.