Vulnerabilities > 3D3 COM

DATE CVE VULNERABILITY TITLE RISK
2002-12-31 CVE-2002-2303 Cryptographic Issues vulnerability in 3D3.Com Shopfactory 5.8
3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart prices by using the Javascript to decrypt the cookie that contains the data.
network
low complexity
3d3-com CWE-310
7.8
2002-12-31 CVE-2002-2302 Permissions, Privileges, and Access Controls vulnerability in 3D3.Com Shopfactory 5.5/5.6/5.8
3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form field.
network
low complexity
3d3-com CWE-264
6.4