Back
CVE-2005-2255
Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via ".." sequences in the lan parameter to (1) index.php or (2) admin/index.php.
Published: Jul 13, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| gianluca_baldo | phpauction | 2.5 |
GitHub Security Advisory GHSA-f5v5-r95w-q486
Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary...
References (4)
- http://secunia.com/advisories/15967
- http://securitytracker.com/id?1014423 Exploit, Vendor Advisory
- http://secunia.com/advisories/15967
- http://securitytracker.com/id?1014423 Exploit, Vendor Advisory
Risk Scores
CVSS Score
6.4 / 10
EPSS Score
1.51%
Top 28% most likely to be exploited
Threat Score
26.1 / 100
Data Sources
NVD
EPSS
GitHub