CVE-2009-4060 – CubeCart 3.0.4/4.3.6 - 'ProductID' SQL Injection
https://notcve.org/view.php?id=CVE-2009-4060
SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter. Una vulnerabilidad de inyección SQL en includes/content/viewProd.inc.php en CubeCart antes de v4.3.7 permite ejecutar comandos SQL a atacantes remotos a través del parámetro ProductID. • https://www.exploit-db.com/exploits/33362 http://forums.cubecart.com/index.php?showtopic=39900 http://osvdb.org/60306 http://secunia.com/advisories/37402 http://www.securityfocus.com/bid/37065 http://www.vupen.com/english/advisories/2009/3290 https://exchange.xforce.ibmcloud.com/vulnerabilities/54331 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2006-5109
https://notcve.org/view.php?id=CVE-2006-5109
Devellion CubeCart 2.0.x allows remote attackers to obtain sensitive information via a direct request for (1) link_navi.php or (2) spotlight.php, which reveals the path in various error messages. NOTE: the information.php, language.php, list_docs.php, popular_prod.php, sale.php, check_sum.php, and cat_navi.php vectors are already covered by CVE-2005-0607. Devellion CubeCart 2.0.x permite a atacantes remotos obtener información sensible a través de la respuesta directa para (1) link_navi.php o (2) spotlight.php, lo cual revela el camino en varios mensajes de error, NOTA: los vectores information.php, language.php, list_docs.php, popular_prod.php, sale.php, check_sum.php, y cat_navi.php están actualmente cubiertos por CVE-2005-0607. • http://securityreason.com/securityalert/1662 http://www.securityfocus.com/archive/1/447009/100/0/threaded http://www.securityfocus.com/bid/20215 https://exchange.xforce.ibmcloud.com/vulnerabilities/29178 •
CVE-2006-5108 – CubeCart 3.0.x - '/admin/header.inc.php' Multiple Cross-Site Scripting Vulnerabilities
https://notcve.org/view.php?id=CVE-2006-5108
Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the order_id parameter in (1) admin/print_order.php and (2) view_order.php; the (3) site_url and (4) la_search_home parameters and (5) certain language parameters in admin/nav.php; the (6) image parameter in admin/image.php; the (7) site_name, (8) la_adm_header, (9) charset, and (10) certain other parameters in admin/header.inc.php; the (12) la_pow_by parameter in footer.inc.php; and the (13) site_name parameter and (14) certain other parameters in header.inc.php. Múltiples vulnerabilidades se secuencias de comandos en sitios cruzados (XSS) en Devellion CubeCart 2.0.x permite a un atacante remoto inyectar secuencias de comandos web o HTML a través del parámetro order_id en (1)admin/print_order.php y (2) view_order.php; los parámetros (3) site_urly (4) la_search_home y ciertos parámetros de lenguaje en admin/nav.php; el parámetro (6) image en admin/image.php;el(7) site_name, (8) la_adm_header, (9) charset, y (10) otros parámetros en admin/header.inc.php; el parámetro(12) la_pow_by parameter en footer.inc.php; y el parámetro (13) site_name y (14) otros parámetros en header.inc.php. • https://www.exploit-db.com/exploits/28703 https://www.exploit-db.com/exploits/28701 https://www.exploit-db.com/exploits/28702 https://www.exploit-db.com/exploits/28699 https://www.exploit-db.com/exploits/28704 https://www.exploit-db.com/exploits/28700 http://secunia.com/advisories/22175 http://securityreason.com/securityalert/1662 http://www.osvdb.org/29246 http://www.osvdb.org/29247 http://www.osvdb.org/29248 http://www.osvdb.org/29249 http://www.os •
CVE-2006-5107 – CubeCart 3.0.x - '/admin/forgot_pass.php?user_name' SQL Injection
https://notcve.org/view.php?id=CVE-2006-5107
Multiple SQL injection vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter in admin/forgot_pass.php, (2) the order_id parameter in view_order.php, (3) the view_doc parameter in view_doc.php, and (4) the order_id parameter in admin/print_order.php. Múltiples vulnerabilidades de inyección SQL en Devellion CubeCart 2.0.x permite a un atacante remoto ejecutar comandos SQL de su elección a través del (1)parámetro user_name en admin/forgot_pass.php, (2) el parámerto order_id en view_order.php, (3) el parámetro view_doc en view_doc.php, y (4) el parámetro order_id en admin/print_order.php. • https://www.exploit-db.com/exploits/28695 https://www.exploit-db.com/exploits/28698 https://www.exploit-db.com/exploits/28697 https://www.exploit-db.com/exploits/28696 http://securityreason.com/securityalert/1662 http://www.securityfocus.com/archive/1/447009/100/0/threaded http://www.securityfocus.com/bid/20215 https://exchange.xforce.ibmcloud.com/vulnerabilities/29176 •
CVE-2006-4526
https://notcve.org/view.php?id=CVE-2006-4526
SQL injection vulnerability in includes/content/viewCat.inc.php in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the searchArray[] parameter. Vulnerabilidad de inyección SQL en includes/content/viewCat.inc.php en CubeCart 3.0.12 y anteriores, cuando register_globales está activado, permite a atacantes remotos ejecutar comandos SQL de su elección mediante el parámetro searchArray[]. • http://cubecart.com/site/forums/index.php?showtopic=21540 http://secunia.com/advisories/21659 http://www.cubecart.com/site/forums/index.php?s=5e34938dc670782af211587b8a450c90&act=Attach&type=post&id=697 http://www.gulftech.org/?node=research&article_id=00111-08282006& http://www.securityfocus.com/bid/19782 •