Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP Toolkit for PayPal IPN_success.PHP Logfile Injection Vulnerability

A vulnerability exists in PHP Toolkit for PayPal which may allow a remote attacker to append entries to the PayPal transaction log file.

An attacker may be able to use this vulnerability to falsely obtain goods and services from a vendor running the affected application, if the vendor can be duped into believing that the goods ordered by the attacker have been paid for.







 

Privacy Statement
Copyright 2009, SecurityFocus