Show filters
32 Total Results
Displaying 11-20 of 32
Sort by:
Attacker Value
Unknown

CVE-2014-10067

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal site or the sandbox. With a bit of time, an attacker could craft a request using the simulator that would fool any application which does not explicitly check for test_ipn in production.
0
Attacker Value
Unknown

CVE-2013-7201

Disclosure Date: April 27, 2018 (last updated November 26, 2024)
WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
0
Attacker Value
Unknown

CVE-2013-7202

Disclosure Date: April 27, 2018 (last updated November 26, 2024)
The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.
0
Attacker Value
Unknown

CVE-2015-9234

Disclosure Date: September 30, 2017 (last updated November 26, 2024)
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has SQL injection via the cp_contactformpp_id parameter to cp_contactformpp.php.
0
Attacker Value
Unknown

CVE-2017-6099

Disclosure Date: February 24, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.
0
Attacker Value
Unknown

CVE-2011-5237

Disclosure Date: November 06, 2012 (last updated October 05, 2023)
PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown

CVE-2012-5802

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown

CVE-2012-5789

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to intentional disabling of certificate-validation checks through a "FALSE" value.
0
Attacker Value
Unknown

CVE-2012-5806

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function, a different vulnerability than CVE-2012-5805.
0
Attacker Value
Unknown

CVE-2012-5791

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0