5
CVSSv2

CVE-2005-1033

Published: 02/05/2005 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 520
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

CubeCart 2.0.6 allows remote malicious users to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.

Vulnerable Product Search on Vulmon Subscribe to Product

devellion cubecart 2.0.6

Exploits

source: wwwsecurityfocuscom/bid/13050/info CubeCart is reported prone to multiple SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries These issues affect the 'indexphp', 'tellafriendphp', 'view_cartphp', and 'view_productphp' ...
source: wwwsecurityfocuscom/bid/13050/info CubeCart is reported prone to multiple SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries These issues affect the 'indexphp', 'tellafriendphp', 'view_cartphp', and 'view_productphp' scri ...
source: wwwsecurityfocuscom/bid/13050/info CubeCart is reported prone to multiple SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries These issues affect the 'indexphp', 'tellafriendphp', 'view_cartphp', and 'view_productphp' sc ...
source: wwwsecurityfocuscom/bid/13050/info CubeCart is reported prone to multiple SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries These issues affect the 'indexphp', 'tellafriendphp', 'view_cartphp', and 'view_productphp ...