Vulnerabilities > CVE-2014-4963 - Unspecified vulnerability in Shopizer 1.1.5

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
shopizer
exploit available

Summary

Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action.

Vulnerable Configurations

Part Description Count
Application
Shopizer
1

Exploit-Db

descriptionShopizer 1.1.5 - Multiple Vulnerabilities. CVE-2014-4962,CVE-2014-4963,CVE-2014-4964,CVE-2014-4965. Webapps exploit for php platform
idEDB-ID:34062
last seen2016-02-03
modified2014-07-14
published2014-07-14
reporterSEC Consult
sourcehttps://www.exploit-db.com/download/34062/
titleShopizer 1.1.5 - Multiple Vulnerabilities