phpcart.php in PHPCart 3.2 allows remote attackers to change product...
Vulnerability Description
phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2) postage parameters. NOTE: it was later reported that 3.4 through 4.6.4 are also affected.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-1398
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/495806/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44766
- http://www.securityfocus.com/bid/13406
- http://secunia.com/advisories/15147
- http://lostmon.blogspot.com/2005/04/phpcart-price-manipulation.html
- http://www.securityfocus.com/bid/30887
- http://www.osvdb.org/15859
Affected Vendor
phpcart
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.