CVE-2000-1001

Executive Summary

Remote attackers can manipulate price data in Element InstantShop’s add_2_basket.asp by altering the hidden "price" form variable, enabling unauthorized price changes and potential financial fraud.


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2000-12-11T05:00:00.000 - Last Modified: 2026-09-23T13:10:00.153

Original Description: add_2_basket.asp in Element InstantShop allows remote attackers to modify price information via the "price" hidden form variable.

"Worry often gives a small thing a big shadow."

— Swedish proverb
Source: NVD