Lucene search

K
cveMitreCVE-2008-6965
HistoryAug 13, 2009 - 4:30 p.m.

CVE-2008-6965

2009-08-1316:30:01
CWE-287
mitre
web.nvd.nist.gov
25
cve-2008-6965
information security
remote attack
authentication bypass
aj auction
web security

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0.007

Percentile

80.1%

AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a direct request to (1) site.php, (2) auction.php, (3) mail.php, (4) fee_setting.php, (5) earnings.php, (6) insertion_fee_settings.php, (7) custom_category.php, (8) subcategory.php, (9) category.php, (10) report.php, (11) store_manager.php, and (12) choose_sell_format.php in admin/, and possibly other vectors.

Affected configurations

Nvd
Node
aj_squareaj_auction
OR
aj_squareaj_auctionMatch1.0pro_platinum_skin
OR
aj_squareaj_auctionMatch2.0pro_platinum_skin
OR
aj_squareaj_auctionMatchweb_2.0
VendorProductVersionCPE
aj_squareaj_auction*cpe:2.3:a:aj_square:aj_auction:*:*:*:*:*:*:*:*
aj_squareaj_auction1.0cpe:2.3:a:aj_square:aj_auction:1.0:*:pro_platinum_skin:*:*:*:*:*
aj_squareaj_auction2.0cpe:2.3:a:aj_square:aj_auction:2.0:*:pro_platinum_skin:*:*:*:*:*
aj_squareaj_auctionweb_2.0cpe:2.3:a:aj_square:aj_auction:web_2.0:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0.007

Percentile

80.1%

Related for CVE-2008-6965