3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart prices by using the Javascript to decrypt the cookie that contains the data.
References
Configurations
History
20 Nov 2024, 23:43
Type | Values Removed | Values Added |
---|---|---|
References | () http://cert.uni-stuttgart.de/archive/bugtraq/2003/03/msg00081.html - | |
References | () http://securityreason.com/securityalert/3263 - | |
References | () http://www.securityfocus.com/archive/1/301863 - | |
References | () http://www.securityfocus.com/bid/6296 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/10746 - |
Information
Published : 2002-12-31 05:00
Updated : 2024-11-20 23:43
NVD link : CVE-2002-2303
Mitre link : CVE-2002-2303
CVE.ORG link : CVE-2002-2303
JSON object : View
Products Affected
3d3.com
- shopfactory
CWE
CWE-310
Cryptographic Issues