The PayPal Website Payments Standard functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal does not properly validate orders, which allows remote attackers to trigger unspecified "duplicate actions" via unknown vectors.
https://exchange.xforce.ibmcloud.com/vulnerabilities/54346
http://www.securityfocus.com/bid/37058