ebay- PrestaShop module vulnerability (CVE-2012-5800)
Moduleebay
Score
5.8 MediumDate publish
04-11-2012Versiones afectadas
- No versions found.
Description
The eBay module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.References
Metrics
| cvssMetricV2 | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| source | nvd@nist.gov | ||||||||||
| type | Primary | ||||||||||
| version | 2.0 | ||||||||||
| vectorString | AV:N/AC:M/Au:N/C:P/I:P/A:N | ||||||||||
| baseScore | 5.8 | ||||||||||
| accessVector | NETWORK | ||||||||||
| accessComplexity | MEDIUM | ||||||||||
| authentication | NONE | ||||||||||
| confidentialityImpact | PARTIAL | ||||||||||
| integrityImpact | PARTIAL | ||||||||||
| availabilityImpact | NONE | ||||||||||
| baseSeverity | MEDIUM | ||||||||||
| exploitabilityScore | 8.6 | ||||||||||
| impactScore | 4.9 | ||||||||||
| acInsufInfo | False | ||||||||||
| obtainAllPrivilege | False | ||||||||||
| obtainUserPrivilege | False | ||||||||||
| obtainOtherPrivilege | False | ||||||||||
| userInteractionRequired | False | ||||||||||
