Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2016-15015
Disclosure Date: January 08, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in viafintech Barzahlen Payment Module PHP SDK up to 2.0.0. Affected is the function verify of the file src/Webhook.php. The manipulation leads to observable timing discrepancy. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 2.0.1 is able to address this issue. The patch is identified as 3e7d29dc0ca6c054a6d6e211f32dae89078594c1. It is recommended to upgrade the affected component. VDB-217650 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2021-43678
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
Wechat-php-sdk v1.10.2 is affected by a Cross Site Scripting (XSS) vulnerability in Wechat.php.
0
Attacker Value
Unknown
CVE-2019-20455
Disclosure Date: February 14, 2020 (last updated February 21, 2025)
Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.
0
Attacker Value
Unknown
CVE-2017-6216
Disclosure Date: July 03, 2019 (last updated November 27, 2024)
novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code execution
0
Attacker Value
Unknown
CVE-2018-19187
Disclosure Date: November 14, 2018 (last updated November 27, 2024)
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement.
0
Attacker Value
Unknown
CVE-2018-19189
Disclosure Date: November 14, 2018 (last updated November 27, 2024)
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.
0
Attacker Value
Unknown
CVE-2018-19190
Disclosure Date: November 14, 2018 (last updated November 27, 2024)
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the error.php error_msg parameter.
0
Attacker Value
Unknown
CVE-2018-19188
Disclosure Date: November 14, 2018 (last updated November 27, 2024)
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fort_id parameter.
0
Attacker Value
Unknown
CVE-2018-19186
Disclosure Date: November 14, 2018 (last updated November 27, 2024)
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the route.php paymentMethod parameter.
0
Attacker Value
Unknown
CVE-2017-6215
Disclosure Date: August 02, 2018 (last updated November 27, 2024)
paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.
0