Smartwin Technology CyberOffice Shopping Cart 2.0 Price Modification Vulnerability

Smartwin Technology CyberOffice Shopping Cart is a shopping cart application for e-commerce enabled websites running Windows NT 4.0 or 2000.

The order form CyberOffice Shopping Cart utilizes can be easily modified by downloading the form locally and then resubmitting it to the target server containing the new values. Unit item prices can be modified to any arbitrary value.


 

Privacy Statement
Copyright 2010, SecurityFocus