Vulnerabilities
Vulnerable Software
Paypal:  >> Paypal  Security Vulnerabilities
WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
CVSS Score
7.4
EPSS Score
0.019
Published
2018-04-27
The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.
CVSS Score
8.1
EPSS Score
0.022
Published
2018-04-27
The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CVSS Score
5.8
EPSS Score
0.006
Published
2012-11-04


Contact Us

Shodan ® - All rights reserved