« Volver al listado

CVE-2012-2991

Estado: ModificadaMedia (5)—

The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-2991",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-09-19T19:55:05.233",
  "references": [
    {
      "url": "http://secunia.com/advisories/50640",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/459446",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/50640",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/459446",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self."
    },
    {
      "lang": "es",
      "value": "El módulo PayPal (también conocido como MODULE_PAYMENT_PAYPAL_STANDARD)anterior a v1.1 en osCommerce Online Merchant anteriores a v2.3.4 permite a atacantes remotos, fijar el receptor de pago a través de un valor modificado en la dirección de correo electrónico del comerciante, como se demostró fijando el valor del receptor a uno mismo.\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:42:28.580",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:oscommerce:online_merchant:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C8EAB89-5625-4D51-B521-A67794BEF423",
              "versionEndIncluding": "2.3.3"
            },
            {
              "criteria": "cpe:2.3:a:oscommerce:online_merchant:2.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2973F415-42D4-4B5F-B6FB-B610D6F0719E"
            },
            {
              "criteria": "cpe:2.3:a:oscommerce:online_merchant:2.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27DE7428-0AAE-42F8-BC28-5FEC86A463E7"
            },
            {
              "criteria": "cpe:2.3:a:oscommerce:online_merchant:2.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D181B92-4836-412C-8B9D-0F56B658916C"
            },
            {
              "criteria": "cpe:2.3:a:paypal:website_payments_standard_module:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BB5E297-9E79-4E93-BBD4-D30E5619CC7A",
              "versionEndIncluding": "1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}