First published: Fri Jan 13 2006(Updated: )
Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Paypal Php Toolkit | <=0.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.