comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to change the prices of items by directly modifying them in the URL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Comersus_cart | Comersus_open_technologies | 5.0.9 (including) | 5.0.9 (including) |