Back

CVE-2005-2255

Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via ".." sequences in the lan parameter to (1) index.php or (2) admin/index.php.

Published: Jul 13, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
gianluca_baldo phpauction 2.5

GitHub Security Advisory GHSA-f5v5-r95w-q486

Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 1.51%

Top 28% most likely to be exploited

Threat Score 26.1 / 100

Data Sources

NVD EPSS GitHub