Show filters
26 Total Results
Displaying 11-20 of 26
Sort by:
Attacker Value
Unknown
CVE-2012-5803
Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The Authorize.Net module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown
CVE-2012-5804
Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The CyberSource module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown
CVE-2012-4482
Disclosure Date: October 31, 2012 (last updated October 05, 2023)
The Ubercart SecureTrading Payment Method module 6.x for Drupal does not properly verify payment notification information, which allows remote attackers to purchase an item without paying via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-2058
Disclosure Date: September 17, 2012 (last updated October 05, 2023)
The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-2057
Disclosure Date: September 17, 2012 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors related to formAPI.
0
Attacker Value
Unknown
CVE-2012-2299
Disclosure Date: August 14, 2012 (last updated October 04, 2023)
The Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal stores passwords for new customers in plaintext during checkout, which allows local users to obtain sensitive information by reading from the database.
0
Attacker Value
Unknown
CVE-2012-2300
Disclosure Date: August 14, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal allow remote authenticated users with the administer product classes permission to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-2731
Disclosure Date: June 27, 2012 (last updated October 04, 2023)
The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.
0
Attacker Value
Unknown
CVE-2012-2702
Disclosure Date: June 27, 2012 (last updated October 04, 2023)
The Ubercart Product Keys module 6.x-1.x before 6.x-1.1 for Drupal does not properly check access for product keys, which allows remote attackers to read all unassigned product keys via certain conditions related to the uid.
0
Attacker Value
Unknown
CVE-2009-4772
Disclosure Date: April 20, 2010 (last updated October 04, 2023)
Unspecified vulnerability in the PayPal Website Payments Standard functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal, when a custom checkout completion message is enabled, allows attackers to obtain sensitive information via unknown vectors.
0