Page 6 of 29 results (0.004 seconds)

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 2

index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message. • https://www.exploit-db.com/exploits/25097 http://marc.info/?l=bugtraq&m=110842125901191&w=2 http://www.cubecart.com/site/forums/index.php?showtopic=5741 http://www.osvdb.org/14064 http://www.securityfocus.com/bid/12549 https://exchange.xforce.ibmcloud.com/vulnerabilities/19328 •

CVSS: 5.0EPSS: 2%CPEs: 2EXPL: 2

Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter. • https://www.exploit-db.com/exploits/25098 http://marc.info/?l=bugtraq&m=110842125901191&w=2 http://marc.info/?l=bugtraq&m=111281888605580&w=2 http://secunia.com/advisories/14272 http://www.cubecart.com/site/forums/index.php?showtopic=5741 http://www.securityfocus.com/bid/12549 https://exchange.xforce.ibmcloud.com/vulnerabilities/19322 •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message. • http://marc.info/?l=bugtraq&m=109713382400457&w=2 https://exchange.xforce.ibmcloud.com/vulnerabilities/17630 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 3

SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. • https://www.exploit-db.com/exploits/15278 http://marc.info/?l=bugtraq&m=109713382400457&w=2 http://secunia.com/advisories/12764 http://www.exploit-db.com/exploits/15278 http://www.securityfocus.com/bid/11337 https://exchange.xforce.ibmcloud.com/vulnerabilities/17632 •