CVE-2012-5806 describes a critical vulnerability in the PayPal Payments Pro module for Zen Cart, where the module fails to properly validate SSL server hostnames against X.509 certificate fields. This oversight, stemming from the use of the PHP fsockopen function, enables man-in-the-middle attackers to spoof legitimate SSL servers using any valid certificate. Rated with a CVSS score of 5.8, this vulnerability has a network attack vector and medium attack complexity, potentially leading to partial compromise of confidentiality and integrity. While the EPSS score is low, indicating a lower likelihood of exploitation, the FAUCET Risk Score of 28/100 suggests a moderate risk. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Furthermore, the vulnerability has garnered minimal community discussion or media coverage, suggesting it is not widely known or actively targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:paypal:payments_pro:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:zen-cart:zen_cart:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.