PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Phpauction |
Gianluca_baldo |
2.5 (including) |
2.5 (including) |
References