Security Advisory
CVE-2012-2058
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors.