October 08, 2003

PayPal Store Front Vulnerability

Securiteam reports that a vulnerability in the product allows remote attackers to include arbitrary PHP files (that are then executed) that can be stored either locally on the server, or remotely.

In other words, your cart is in doodoo if an attacker decides they wish to include an external file and execute arbitrary commands with the privileges of the web server. (Typically www-data or nobody)

Credits to Astharot over at Zone-h for the original security advisory.

So, if you are using the PayPal store front for you eBusiness... you might wanna look into this.

Posted by SilverStr at October 8, 2003 05:56 PM | TrackBack
Comments

Interesting....


/me goes back to coding on a credit card store front system

Posted by: Wim at October 8, 2003 11:22 PM

Also got a nice paypal fake 'verify your information' email, up on ufies.org. *sigh* I hate society these days.

Posted by: Arcterex at October 9, 2003 02:10 PM