CVE-2013-0118
Published Feb 24, 2013
Last updated 12 years ago
Overview
- Description
- CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.
- Source
- cret@cert.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-16
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cs-cart:cs-cart:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91F91E50-9B37-4CC7-B27C-331739A27351", "versionEndIncluding": "3.0.5" }, { "criteria": "cpe:2.3:a:cs-cart:cs-cart:3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52F3E4CE-4A77-42CE-9F57-B5D05CCF05D3" }, { "criteria": "cpe:2.3:a:cs-cart:cs-cart:3.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4BA204ED-767B-4928-8870-33B25A10F3A4" }, { "criteria": "cpe:2.3:a:cs-cart:cs-cart:3.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BB2D439E-F3D1-4D3A-90EC-50EE09CAD1A5" }, { "criteria": "cpe:2.3:a:cs-cart:cs-cart:3.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "99F8E1C7-C33F-4BC9-A560-50439233F53E" } ], "operator": "OR" } ] } ]