5.8
CVSSv2

CVE-2011-5238

Published: 06/11/2012 Updated: 06/11/2012
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

google-checkout-php-sample-code prior to 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary valid certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

google checkout-php 1.2.1

google checkout-php 1.2

google checkout-php

google checkout-php 1.2.5a

google checkout-php 1.3.0

google checkout-php 1.2.5