3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart prices by using the Javascript to decrypt the cookie that contains the data.
References
Configurations
Information
Published : 2002-12-30 21:00
Updated : 2017-07-28 18:29
NVD link : CVE-2002-2303
Mitre link : CVE-2002-2303
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
3d3.com
- shopfactory