An issue was discovered in a smart contract implementation for AIRDROPX BORN through 2019-05-29, an Ethereum token. The name of the constructor has a typo (wrong case: XBornID versus XBORNID) that allows an attacker to change the owner of the contract and obtain cryptocurrency for free.
References
Link Resource
https://github.com/smsecgroup/SM-VUL/tree/master/typo-vul-00 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-12-30T19:53:56

Updated: 2020-12-30T19:53:56

Reserved: 2019-08-15T00:00:00


Link: CVE-2019-15078

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-12-30T20:15:14.847

Modified: 2021-01-04T20:09:03.537


Link: CVE-2019-15078

JSON object: View

cve-icon Redhat Information

No data.