Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2014-5611

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The eBay Kleinanzeigen for Germany (aka com.ebay.kleinanzeigen) application 5.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2012-5801

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The PayPal module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.
0
Attacker Value
Unknown

CVE-2012-5800

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The eBay module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown

CVE-2010-2144

Disclosure Date: June 03, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in signinform.php in Zeeways eBay Clone Auction Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-3712

Disclosure Date: October 16, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php; and the item_id parameter to (2) view_full_size.php, (3) classifide_ad.php, and (4) crosspromoteitems.php.
0
Attacker Value
Unknown

CVE-2009-2894

Disclosure Date: August 20, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to product_desc.php, and the cid parameter to (2) showcategory.php and (3) gallery.php.
0
Attacker Value
Unknown

CVE-2009-2424

Disclosure Date: July 10, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in Ebay Clone 2009 allows remote attackers to inject arbitrary web script or HTML via the mode parameter.
0
Attacker Value
Unknown

CVE-2009-2423

Disclosure Date: July 10, 2009 (last updated October 04, 2023)
SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list action.
0