Логотип exploitDog
bind:CVE-2008-7310
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2008-7310

Количество 2

Количество 2

nvd логотип

CVE-2008-7310

почти 14 лет назад

Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability.

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-7h48-m3rw-vr27

больше 3 лет назад

Spree does not properly restrict the use of a hash to provide values for a model's attributes

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-7310

Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability.

CVSS2: 5
0%
Низкий
почти 14 лет назад
github логотип
GHSA-7h48-m3rw-vr27

Spree does not properly restrict the use of a hash to provide values for a model's attributes

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу