CVE-2012-5796: Input Validation
The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5796?
CVE-2012-5796 is classified as a high severity vulnerability due to the potential for man-in-the-middle attacks.
How do I fix CVE-2012-5796?
To mitigate CVE-2012-5796, ensure that your server is configured to verify the hostname against the X.509 certificate.
What software is affected by CVE-2012-5796?
CVE-2012-5796 affects both osCommerce and the PayPal Pro module.
What type of attack can CVE-2012-5796 facilitate?
CVE-2012-5796 can facilitate man-in-the-middle attacks by allowing attackers to spoof SSL servers.
Is CVE-2012-5796 still a relevant vulnerability?
Yes, CVE-2012-5796 remains relevant, especially for users running vulnerable versions of osCommerce and PayPal Pro.