vendor:
AJ Auction
by:
G4N0K
5.5
CVSS
MEDIUM
Authentication bypass
287
CWE
Product Name: AJ Auction
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2008
AJ Auction Auth Bypass Vulnerability
The AJ Auction script is vulnerable to an authentication bypass vulnerability. This allows an attacker to access administrative pages without proper authentication.
Mitigation:
The vendor should release a patch to fix the authentication bypass vulnerability. In the meantime, users should implement strong passwords and restrict access to administrative pages.