exploit-db-mirror/exploits/php/webapps/30429.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

11 lines
No EOL
604 B
Text

source: http://www.securityfocus.com/bid/25116/info
phpCoupon is prone to a remote payment-bypass vulnerability because the application fails to properly secure PayPal payment transactions.
Successfully exploiting this issue allows remote attackers to perform payment transactions in the application without actually paying money. This allows them to obtain services for free.
The following URI demonstrates this issue:
http://www.example.com/path/user.php?REQ=auth&billing=141&status=success&custom=upgrade5
The '141' and the 'upgrade5' values may vary from installation to installation.