CVE-2005-2220 (CNNVD-200507-139)
中文标题:
incredibleinteractive DragonflyCommerce 多个 数据篡改漏洞
英文标题:
Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCar...
漏洞描述
中文描述:
Dragonfly Commerce是一套电子商务网站解决方案。 Dragonfly Commerce存在数据篡改漏洞。 远程攻击者可通过修改dc_Categorieslist.asp、dc_Categoriesview.asp、dc_productslist.asp及dc_productslist_Clearance.asp中的x_DragonflyCartProductPrice隐藏字段来更改产品价格。 注:供应商对此问题有异议。
英文描述:
Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden field to (1) dc_Categorieslist.asp, (2) dc_Categoriesview.asp, (3) dc_productslist.asp, and (4) dc_productslist_Clearance.asp. NOTE: the vendor has disputed this issue, saying that "Dragonfly Commerce does not allow for editing prices nor does it allow for viewing information about clients stored in the database except by the store owner and authorized staff as appointed in the store administration." However, SecurityTracker claims that they have been able to confirm the problem
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| incredible_interactive | dragonfly_commerce | * | - | - |
cpe:2.3:a:incredible_interactive:dragonfly_commerce:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
AV:N/AC:L/Au:N/C:N/I:P/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2005-2220 |
2025-11-11 15:17:35 | 2025-11-11 07:32:27 |
| NVD | nvd_CVE-2005-2220 |
2025-11-11 14:51:19 | 2025-11-11 07:41:13 |
| CNNVD | cnnvd_CNNVD-200507-139 |
2025-11-11 15:08:47 | 2025-11-11 07:48:59 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200507-139
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 5.0
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:N/C:N/I:P/A:N
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']