CVE-2000-0926
Executive Summary
SmartWin CyberOffice Shopping Cart 2 (CyberShop) is vulnerable to remote manipulation of hidden form fields, enabling attackers to alter the 'Price' variable and defraud customers. The flaw arises from insufficient input validation on the 'Price' field, allowing unauthorized price changes without authentication. This can lead to financial loss and reputational damage for merchants using the affected version. The vulnerability is not currently listed in the CISA KEV database.
Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2000-12-19T05:00:00.000 - Last Modified: 2026-09-25T17:10:00.133
Original Description: SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable.
"One that desires to excel should endeavour in those things that are in themselves most excellent."
— Epictetus