CVE-2008-6535

Paypalestores Paypal Estores - Access Control

Title source: rule

Description

admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a direct request with a modified NewAdmin parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by G4N0K · phpwebappsphp
https://www.exploit-db.com/exploits/7367

Scores

EPSS 0.0138
EPSS Percentile 80.3%

Details

CWE
CWE-264
Status published
Products (1)
paypalestores/paypal_estores
Published Mar 26, 2009
Tracked Since Feb 18, 2026