Unrated severityNVD Advisory· Published Aug 19, 2009· Updated Apr 23, 2026
CVE-2008-6999
CVE-2008-6999
Description
phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
Affected products
2cpe:2.3:a:phpauction:phpauction:3.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:phpauction:phpauction:3.2:*:*:*:*:*:*:*
- cpe:2.3:a:phpauction:phpauction:3.3.0:*:gpl_basic:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- osvdb.org/47939nvdExploit
- packetstorm.linuxsecurity.com/0809-exploits/phpauction32-rfi.txtnvdExploit
- secunia.com/advisories/31803nvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/44936nvd
News mentions
0No linked articles in our index yet.