5
CVSSv2

CVE-2005-0607

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

CubeCart 2.0.0 up to and including 2.0.5 allows remote malicious users to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) list_docs.php, (4) popular_prod.php, (5) sale.php, (6) subfooter.inc.php, (7) subheader.inc.php, (8) cat_navi.php, or (9) check_sum.php, which reveals the path in a PHP error message.

Vulnerable Product Search on Vulmon Subscribe to Product

devellion cubecart 2.0.3

devellion cubecart 2.0.1

devellion cubecart 2.0.2

devellion cubecart 2.0.5

devellion cubecart 2.0.0