Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ECW Shop Order Input Validation Vulnerability

ECW Shop is prone to a remote input validation vulnerability. The issue exists because the software fails to sufficiently sanitize URI parameter data that is employed when computing product charges.


A remote attacker may exploit this issue to manipulate invoice and payment charges for a specific ECW Shop order.







 

Privacy Statement
Copyright 2009, SecurityFocus