CyberSec.Space Logo
返回 CVE 浏览器

CVE-2005-2220

MEDIUM
5.0
CVSS Severity Score
EPSS Score0.1460%
EPSS Percentile22.14th
Published2005年7月12日
Last Modified2026年4月16日

Vulnerability Description

Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden field to (1) dc_Categorieslist.asp, (2) dc_Categoriesview.asp, (3) dc_productslist.asp, and (4) dc_productslist_Clearance.asp. NOTE: the vendor has disputed this issue, saying that "Dragonfly Commerce does not allow for editing prices nor does it allow for viewing information about clients stored in the database except by the store owner and authorized staff as appointed in the store administration." However, SecurityTracker claims that they have been able to confirm the problem

Affected Platforms (CPE)

📦
Incredible Interactive

Dragonfly Commerce

All versions

References & Advisories

相关漏洞威胁