4.3
CVSSv2

CVE-2006-4525

Published: 01/09/2006 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and previous versions, when register_globals is enabled, allows remote malicious users to inject arbitrary web script or HTML via the links array.

Vulnerable Product Search on Vulmon Subscribe to Product

devellion cubecart

Exploits

CubeCart Multiple Vulnerabilities Vendor: Devellion Limited Product: CubeCart Version: <= 3012 Website: wwwcubecartcom BID: 19782 CVE: CVE-2006-4525 OSVDB: 28279 28280 28281 SECUNIA: 21659 Description: CubeCart is a very popular web application written in php that allows for an individual to open up a fully functioning online e ...