Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zachary Mathis

Researcher fromProactive Defense (Kobe Digital Labo)
#21262of 53,634
11.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2013-5143
5.8
2013-08-21
Yahoo! Japan · Yafuoku! · CVE-2013-4699
**Name of the Vulnerable Software and Affected Versions** Yahoo! Japan Yafuoku! application versions 4.3.0 and earlier **Description** The issue allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, as the application does not verify X.509 certificates from SSL servers. **Recommendations** For versions 4.3.0 and earlier, update to a version that properly verifies X.509 certificates to prevent man-in-the-middle attacks.
PT-2013-5144
5.8
2013-08-21
Yahoo! Japan · Yahoo! Japan Shopping · CVE-2013-4700
**Name of the Vulnerable Software and Affected Versions** Yahoo! Japan Shopping application version 1.4 and earlier **Description** The issue allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, as the application does not verify X.509 certificates from SSL servers. **Recommendations** For versions 1.4 and earlier, update to a version that properly verifies X.509 certificates to prevent man-in-the-middle attacks.