Vendors3d3.comshopfactoryall versions
Vulnerabilities

3d3.com Shopfactory

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2002-2303
3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart prices by using the Javascript to decrypt the cookie that contains the data.
Published 2007-10-18 · Modified
7.8EPSS 0.010
CVE-2002-2302
3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form field.
Published 2007-10-18 · Modified
6.4EPSS 0.012