Vulnerability CVE-2006-0202


Published: 2006-01-13   Modified: 2012-02-12

Description:
Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writable permissions for ipn/logs, which allows local users to delete or replace payment data.

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.6/10
4.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
Paypal -> Php toolkit 

 References:
http://www.vupen.com/english/advisories/2006/0183
http://www.uinc.ru/articles/vuln/ptpaypal050.shtml
http://www.securityfocus.com/bid/16218
http://www.securityfocus.com/archive/1/421739
http://secunia.com/advisories/18444
http://www.osvdb.org/22379

Copyright 2024, cxsecurity.com

 

Back to Top