2.9
CVSSv2

CVE-2010-4211

Published: 09/11/2010 Updated: 17/08/2017
CVSS v2 Base Score: 2.9 | Impact Score: 2.9 | Exploitability Score: 5.5
VMScore: 258
Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The PayPal app prior to 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle malicious users to spoof a PayPal web server via an arbitrary certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

ebay paypal