5

CVE-2009-4771

The PayPal Website Payments Standard functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal does not properly validate orders, which allows remote attackers to trigger unspecified "duplicate actions" via unknown vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ubercart ≫ Ubercart Version 5.x-1.0
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha1
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha2
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha3
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha4
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha5
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha6
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha6b
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha6c
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha7
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha7b
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha7c
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha7d
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha7e
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update alpha8
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update beta1
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update beta2
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update beta3
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update beta4
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update beta5
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update beta6
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update beta7
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update rc1
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update rc2
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update rc3
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update rc4
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.0 Update rc5
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.1
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.2
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.3
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.3 Update rc1
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.4
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.5
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.6
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.7
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 5.x-1.8
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta1
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta2
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta3
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta4
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta5
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta6
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update dev
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc1
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc2
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc3
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc4
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc5
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc6
   Drupal ≫ Drupal
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc7
   Drupal ≫ Drupal
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.22% 0.648
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://drupal.org/node/636576
Patch
Vendor Advisory
http://osvdb.org/60290
http://secunia.com/advisories/37440
Vendor Advisory
http://www.securityfocus.com/bid/37058
https://exchange.xforce.ibmcloud.com/vulnerabilities/54346