Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ebay PayPal app授权问题漏洞
Vulnerability Description
基于iOS的PayPal app 3.0.1之前的版本不能验证与X.509证书的主体域名相匹配的服务器主机名。中间人攻击者可以借助任意证书欺骗PayPal web服务器。
CVSS Information
N/A
Vulnerability Type
N/A