search menu icon-carat-right cmu-wordmark

CERT Coordination Center

eBay web site allows intruders to login to gain unauthorized access to user's information

Vulnerability Note VU#791307

Original Release Date: 2002-07-11 | Last Revised: 2010-10-07

Overview

Ebay (www.ebay.com)is a popular online auction site. A vulnerability in the ebay web site prior to April 24, 2002, could have allowed an intruder to gain access to a victim's personal data.

Description

Prior to April 24, 2002, an intruder may have been able to gain access to certain personal data of ebay users, including transaction history and shipping addresses, but not including credit card data. By submitting a certain type of invalid login request to the ebay web site, an intruder could log in as a legitimate user to the "My Ebay" portion of the web site. There is no evidence that anyone used this vulnerability to gain unauthorized access to data.

Impact

Personal information of ebay users may have been exposed to third parties.

Solution

No action is required on the part of ebay users. Ebay corrected the flaw on April 24, 2002.

Vendor Information

791307
 

EBay Affected

Notified:  April 24, 2002 Updated: June 05, 2002

Statement Date:   April 24, 2002

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Addendum

EBay has reported that this vulnerability has been corrected as of 4/24/2002.

If you have feedback, comments, or additional information about this vulnerability, please send us email.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Our thanks to Brent Barnett IT Consultant for reporting this vulnerability and technical assistance.

This document was written by Shawn Hernan.

Other Information

CVE IDs: None
Severity Metric: 0.90
Date Public: 2002-07-11
Date First Published: 2002-07-11
Date Last Updated: 2010-10-07 13:09 UTC
Document Revision: 13

Sponsored by CISA.