Back to Database
Status published
High
CVE-2008-6966
AJ Square AJ Auction Pro Platinum Skin #1 sends a...
Vulnerability Description
AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass authentication via a direct request to admin/user.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-6966
Credits & Attribution
No credits recorded in the NVD database.
References
More from aj square
View All →CVE-2008-6965
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro...
High
7.5
CVE-2008-6414
SQL injection vulnerability in detail.php in AJ Auction Pro Platinum...
High
7.5
CVE-2008-6004
Cross-site scripting (XSS) vulnerability in search.php in AJ Auction Pro...
Medium
4.3
CVE-2008-6003
SQL injection vulnerability in sellers_othersitem.php in AJ Auction Pro Platinum...
High
7.5
CVE-2008-5216
SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0...
High
7.5
Affected Vendor
aj square
View all reports →Affected Software
aj auction
Vulnerable Versions:
1.0
Timeline
Official Publish:
August 13th, 2009
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.