3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart prices by using the Javascript to decrypt the cookie that contains the data.
                
            References
                    Configurations
                    History
                    No history.
Information
                Published : 2002-12-31 05:00
Updated : 2017-07-29 01:29
NVD link : CVE-2002-2303
Mitre link : CVE-2002-2303
CVE.ORG link : CVE-2002-2303
JSON object : View
Products Affected
                3d3.com
- shopfactory
CWE
                
                    
                        
                        CWE-310
                        
            Cryptographic Issues
