PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Phpauction | Gianluca_baldo | 2.5 (including) | 2.5 (including) |
References