Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-0202

Опубликовано: 13 янв. 2006
Источник: nvd
CVSS2: 3.6
EPSS Низкий

Описание

Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writable permissions for ipn/logs, which allows local users to delete or replace payment data.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:paypal:php_toolkit:*:*:*:*:*:*:*:*
Версия до 0.50 (включая)

EPSS

Процентиль: 18%
0.00059
Низкий

3.6 Low

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writable permissions for ipn/logs, which allows local users to delete or replace payment data.

EPSS

Процентиль: 18%
0.00059
Низкий

3.6 Low

CVSS2

Дефекты

NVD-CWE-Other