Phpauction is a PHP-based auction platform with a compact product footprint centered on its core phpauction and phpauction_gpl offerings. The disclosed vulnerabilities cluster around web-application input handling, chiefly code injection, SQL injection, and exposure of sensitive information, reflecting the interpretation and database-query risks inherent to dynamically scripted e-commerce systems. Live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpauction over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1416MEDIUM Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) conver | Mar 20, 2008 | 6.8 | 47 | NO | YES |
CVE-2008-7000HIGH PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be re | Aug 19, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-2900HIGH SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jun 27, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-6999MEDIUM phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo funct | Aug 19, 2009 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpauction.
Media articles that mention a CVE ID that affects a product developed by Phpauction — matched by CVE ID, not by vendor name.