CVE-2002-0995

login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table.

Scoring

CVSS base score
0.29
EPSS probability
7.13%
Published
2003-04-02
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs