CVE-2006-2527

phpBazar <2.1.0 - Auth Bypass

Title source: llm

Description

Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unauthorized access to the administrative section by setting the action parameter to edit_member and the value parameter to 1.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/1804

Scores

EPSS 0.0753
EPSS Percentile 91.8%

Details

Status published
Products (1)
smartisoft/phpbazar 2.1.0
Published May 22, 2006
Tracked Since Feb 18, 2026