Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-0682. PoCs published by Thomas Ryan.
AI-analyzed exploit summary This exploit demonstrates a parameter manipulation vulnerability in Comersus Cart, allowing an attacker to modify the price of an order by tampering with the OrderTotal parameter. The provided URL shows a crafted request with altered pricing values.
Description
comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to change the prices of items by directly modifying them in the URL.
Exploits (1)
This exploit demonstrates a parameter manipulation vulnerability in Comersus Cart, allowing an attacker to modify the price of an order by tampering with the OrderTotal parameter. The provided URL shows a crafted request with altered pricing values.