CVE-2010-4211
Ebay Paypal < 3.0 - Authentication Bypass
Title source: ruleDescription
The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate.
References (8)
Scores
EPSS
0.0008
EPSS Percentile
24.6%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
ebay/paypal
< 3.0
Timeline
Published
Nov 09, 2010
Tracked Since
Feb 18, 2026