5.8
CVSSv2

CVE-2012-0865

Published: 21/02/2012 Updated: 11/01/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 595
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Multiple open redirect vulnerabilities in CubeCart 3.0.20 and previous versions allow remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) r parameter to switch.php or (2) goto parameter to admin/login.php.

Vulnerable Product Search on Vulmon Subscribe to Product

cubecart cubecart

cubecart cubecart 3.0.13

cubecart cubecart 3.0.12

cubecart cubecart 3.0.15

cubecart cubecart 3.0.14

cubecart cubecart 3.0.7

cubecart cubecart 3.0.6

cubecart cubecart 3.0.19

cubecart cubecart 3.0.18

cubecart cubecart 3.0.11

cubecart cubecart 3.0.10

cubecart cubecart 3.0.2

cubecart cubecart 3.0.1

cubecart cubecart 3.0.5

cubecart cubecart 3.0.4

cubecart cubecart 3.0.3

cubecart cubecart 3.0.17

cubecart cubecart 3.0.16

cubecart cubecart 3.0.9

cubecart cubecart 3.0.8

cubecart cubecart 3.0.0

Exploits

source: wwwsecurityfocuscom/bid/51966/info CubeCart is prone to a URI-redirection vulnerabilities because the application fails to properly sanitize user-supplied input A successful exploit may aid in phishing attacks; other attacks are possible CubeCart 3020 is vulnerable; other versions may also be affected wwwexa ...
source: wwwsecurityfocuscom/bid/51966/info CubeCart is prone to a URI-redirection vulnerabilities because the application fails to properly sanitize user-supplied input A successful exploit may aid in phishing attacks; other attacks are possible CubeCart 3020 is vulnerable; other versions may also be affected wwwexamplec ...
source: wwwsecurityfocuscom/bid/51966/info CubeCart is prone to a URI-redirection vulnerabilities because the application fails to properly sanitize user-supplied input A successful exploit may aid in phishing attacks; other attacks are possible CubeCart 3020 is vulnerable; other versions may also be affected wwwexampl ...