RSS   Vulnerabilities for 'Shopfactory'   RSS

2002-12-31
 
CVE-2002-2303

 

 
3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart prices by using the Javascript to decrypt the cookie that contains the data.

 
 
CVE-2002-2302

 

 
3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form field.

 


Copyright 2024, cxsecurity.com

 

Back to Top