5
CVSSv2

CVE-2005-1398

Published: 03/05/2005 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

phpcart.php in PHPCart 3.2 allows remote malicious users to change product price information by modifying the (1) price or (2) postage parameters. NOTE: it was later reported that 3.4 up to and including 4.6.4 are also affected.

Vulnerable Product Search on Vulmon Subscribe to Product

phpcart phpcart 3.2

phpcart phpcart 3.4

phpcart phpcart 4.6.4

Exploits

source: wwwsecurityfocuscom/bid/13406/info PHPCart is prone to a remote input validation vulnerability The issue exists because the software fails to sufficiently sanitize URI parameter data that is employed when computing product charges A remote attacker may exploit this issue to manipulate invoice and payment charges for a specific ...