vendor:
eStore
by:
G4N0K
7.5
CVSS
HIGH
Unauthorized Password Change
CWE
Product Name: eStore
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2008
PayPal eStore Admin Password Changing Exploit
This exploit allows an attacker to change the admin password of the PayPal eStore PHP script. The vulnerability was discovered by G4N0K in November-December 2008. The exact details of the exploit are not mentioned in the text.
Mitigation:
Upgrade to a newer version of the PayPal eStore script that includes a patch for this vulnerability.