Количество 2
Количество 2
CVE-2014-10067
paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal site or the sandbox. With a bit of time, an attacker could craft a request using the simulator that would fool any application which does not explicitly check for test_ipn in production.
GHSA-h698-r4hm-w94p
Validation Bypass in paypal-ipn
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2014-10067 paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal site or the sandbox. With a bit of time, an attacker could craft a request using the simulator that would fool any application which does not explicitly check for test_ipn in production. | CVSS3: 5.9 | 0% Низкий | больше 7 лет назад | |
GHSA-h698-r4hm-w94p Validation Bypass in paypal-ipn | CVSS3: 5.9 | 0% Низкий | больше 5 лет назад |
Уязвимостей на страницу