CVE

Id
9637  
CVE No.
CVE-2004-1209  
Status
Candidate  
Description
Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase.  
Phase
Assigned (20041214)  
Votes
None (candidate not yet proposed)  
Comments