Page 7 of 35 results (0.004 seconds)

CVSS: 5.0EPSS: 0%CPEs: 5EXPL: 0

CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) list_docs.php, (4) popular_prod.php, (5) sale.php, (6) subfooter.inc.php, (7) subheader.inc.php, (8) cat_navi.php, or (9) check_sum.php, which reveals the path in a PHP error message. • http://lostmon.blogspot.com/2005/02/cubecart-20x-multiple-variable-xss.html http://securitytracker.com/id?1013304 http://www.cubecart.com/site/forums/index.php?showtopic=6032 https://exchange.xforce.ibmcloud.com/vulnerabilities/20638 •

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 2

index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message. • https://www.exploit-db.com/exploits/25097 http://marc.info/?l=bugtraq&m=110842125901191&w=2 http://www.cubecart.com/site/forums/index.php?showtopic=5741 http://www.osvdb.org/14064 http://www.securityfocus.com/bid/12549 https://exchange.xforce.ibmcloud.com/vulnerabilities/19328 •

CVSS: 5.0EPSS: 2%CPEs: 2EXPL: 2

Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter. • https://www.exploit-db.com/exploits/25098 http://marc.info/?l=bugtraq&m=110842125901191&w=2 http://marc.info/?l=bugtraq&m=111281888605580&w=2 http://secunia.com/advisories/14272 http://www.cubecart.com/site/forums/index.php?showtopic=5741 http://www.securityfocus.com/bid/12549 https://exchange.xforce.ibmcloud.com/vulnerabilities/19322 •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message. • http://marc.info/?l=bugtraq&m=109713382400457&w=2 https://exchange.xforce.ibmcloud.com/vulnerabilities/17630 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 3

SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. • https://www.exploit-db.com/exploits/15278 http://marc.info/?l=bugtraq&m=109713382400457&w=2 http://secunia.com/advisories/12764 http://www.exploit-db.com/exploits/15278 http://www.securityfocus.com/bid/11337 https://exchange.xforce.ibmcloud.com/vulnerabilities/17632 •