Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase.
References
Configurations
History
20 Nov 2024, 23:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=110181288820226&w=2 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/18299 - |
Information
Published : 2005-01-10 05:00
Updated : 2024-11-20 23:50
NVD link : CVE-2004-1209
Mitre link : CVE-2004-1209
CVE.ORG link : CVE-2004-1209
JSON object : View
Products Affected
verisign
- payflow_link
CWE