Vulnerability in eBay India Allows to buy Anything for one Rupee

Indian Information Security researcher Ishwar Prasad Bhat found a Vulnerability in eBay India that allows to buy for any product for one rupee.

Ishwar told that this vulnerability allows anyone to buy anything for just one rupee by using a fake coupon code. The value of the code is hidden within the page itself. when three wrong tries, the online page asks for a verification code which may be obtained from the Gift String within the source code. By simply modifying the worth for the coupon code to testtes123, you can buy anything from eBay.

You can find more about this on The Hackers Post.

No comments:

Post a Comment