NA

CVE-2024-34832

Published: 06/06/2024 Updated: 07/06/2024

Vulnerability Summary

Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an malicious user to execute arbitrary code via a crafted file uploaded to the _g and node parameters.

Github Repositories

CVE-2024-34832

CubeCart - Directory Traversal May Lead To RCE (CVE-2024-34832) TL;DR In the admin panel, parameters such as _g and node are used to construct the path to include incphp files and execute PHP code A malicious user with the ability to upload incphp files anywhere on the server can exploit a path traversal vulnerability to include them and execute malicious code Prerequisit