3 results (0.002 seconds)

CVSS: 9.1EPSS: 1%CPEs: 4EXPL: 2

13 Aug 2009 — AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a direct request to (1) site.php, (2) auction.php, (3) mail.php, (4) fee_setting.php, (5) earnings.php, (6) insertion_fee_settings.php, (7) custom_category.php, (8) subcategory.php, (9) category.php, (10) report.php, (11) store_manager.php, and (12) choose_sell_format.php in admin/, and possibly... • https://www.exploit-db.com/exploits/7087 • CWE-287: Improper Authentication •

CVSS: 9.8EPSS: 1%CPEs: 1EXPL: 2

13 Aug 2009 — AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass authentication via a direct request to admin/user.php. AJ Square AJ Auction Pro Platinum Skin #1 envía una redirección pero no existe cuando es llamada directamente, lo que permite a los atacantes remotos evitar la autenticación a través de una petición directa a admin/user.php. • https://www.exploit-db.com/exploits/7087 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 9.8EPSS: 0%CPEs: 4EXPL: 2

24 Nov 2008 — SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the item_id parameter. Vulnerabilidad de inyección SQL en classifide_ad.php en AJ Auction v6.2.1 y versiones anteriores permite a atacantes remotos ejecutar comandos SQL de su elección mediante el parámetro "item_id". • https://www.exploit-db.com/exploits/5591 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •