Unrated severityNVD Advisory· Published Sep 19, 2012· Updated Apr 29, 2026
CVE-2012-2991
CVE-2012-2991
Description
The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.
Affected products
5cpe:2.3:a:oscommerce:online_merchant:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:oscommerce:online_merchant:*:*:*:*:*:*:*:*range: <=2.3.3
- cpe:2.3:a:oscommerce:online_merchant:2.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oscommerce:online_merchant:2.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:oscommerce:online_merchant:2.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:paypal:website_payments_standard_module:*:*:*:*:*:*:*:*Range: <=1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.kb.cert.org/vuls/id/459446nvdUS Government Resource
- secunia.com/advisories/50640nvd
News mentions
0No linked articles in our index yet.