20001002 DST2K0036: Price modification possible in CyberOffice Shopping Ca rtmailing list
http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0000.html CVE-2000-0926
Smartwin Technology CyberOffice Shopping Cart 2.0 - Price Modification
Record summary
CVE-2000-0926 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSmartwin Technology CyberOffice Shopping Cart 2.0 - Price ModificationExploitDB exploitby Delphis ConsultingNot analyzed1 file
References
520001002 DST2K0036: Price modification possible in CyberOffice Shopping Cartmailing list
http://marc.info/?l=bugtraq&m=97050627707128&w=2 1733vdb entry
http://www.securityfocus.com/bid/1733 cyberoffice-price-modification(5319)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5319 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0926