phpauction CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

phpauction vulnerability overview

Aggregates CVE and security vulnerability intelligence across all phpauction-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk sql injection and vendor risk path handling; exposure may include vendor impact file overwrite and vendor impact data exposure in vendor surface software deployment contexts.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2008-7000 PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be related to CVE-2005-2255.1. [email protected] 7.5 0.73% 2009-08-19 2026-04-23
CVE-2008-6999 phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. [email protected] 5.0 0.32% 2009-08-19 2026-04-23
CVE-2008-2900 SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. [email protected] 7.5 0.46% 2008-06-27 2026-04-23
CVE-2008-1416 Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) converter.inc.php, (2) messages.inc.php, and (3) settings.inc.php in includes/. [email protected] 6.8 9.68% 2008-03-20 2026-04-23
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence