4
CVSSv2

CVE-2007-4143

Published: 03/08/2007 Updated: 15/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

user.php in the Billing Control Panel in phpCoupon allows remote authenticated users to obtain Premium Member status, and possibly acquire free coupons, via a modified URL containing a certain billing parameter and REQ=auth, status=success, and custom=upgrade substrings, possibly related to PayPal transactions.

Vulnerable Product Search on Vulmon Subscribe to Product

phpcoupon phpcoupon

Exploits

source: wwwsecurityfocuscom/bid/25116/info phpCoupon is prone to a remote payment-bypass vulnerability because the application fails to properly secure PayPal payment transactions Successfully exploiting this issue allows remote attackers to perform payment transactions in the application without actually paying money This allows them ...