6.8
CVSSv2

CVE-2014-2341

Published: 22/04/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Session fixation vulnerability in CubeCart prior to 5.2.9 allows remote malicious users to hijack web sessions via the PHPSESSID parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cubecart cubecart 5.2.7

cubecart cubecart 5.2.3

cubecart cubecart 5.2.2

cubecart cubecart 5.2.5

cubecart cubecart 5.2.4

cubecart cubecart 5.2.6

cubecart cubecart

cubecart cubecart 5.2.1

cubecart cubecart 5.2.0

Exploits

# Exploit Title: CubeCart 528 Session Fixation # Exploit Author: James Sibley (absane) # Blog: wwwpentesterco # Download link: wwwcubecartcom/download/528/zip # Discovery date: March 14th, 2014 # Vendor notified: March 15th, 2014 # Vendor fixed: April 10th, 2014 # Vendor ack: for ...