2.6
CVSSv2

CVE-2006-4527

Published: 01/09/2006 Updated: 05/09/2008
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

includes/content/gateway.inc.php in CubeCart 3.0.12 and previous versions, when magic_quotes_gpc is disabled, uses an insufficiently restrictive regular expression to validate the gateway parameter, which allows remote malicious users to conduct PHP remote file inclusion attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

devellion cubecart 3.0.12