CVE-2005-0442 – Brooky CubeCart 2.0.1/2.0.4 - 'index.php?language' Traversal Arbitrary File Access
https://notcve.org/view.php?id=CVE-2005-0442
Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter. • https://www.exploit-db.com/exploits/25098 http://marc.info/?l=bugtraq&m=110842125901191&w=2 http://marc.info/?l=bugtraq&m=111281888605580&w=2 http://secunia.com/advisories/14272 http://www.cubecart.com/site/forums/index.php?showtopic=5741 http://www.securityfocus.com/bid/12549 https://exchange.xforce.ibmcloud.com/vulnerabilities/19322 •
CVE-2004-1579
https://notcve.org/view.php?id=CVE-2004-1579
index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message. • http://marc.info/?l=bugtraq&m=109713382400457&w=2 https://exchange.xforce.ibmcloud.com/vulnerabilities/17630 •
CVE-2004-1580 – Brooky CubeCart 2.0.1 - SQL Injection
https://notcve.org/view.php?id=CVE-2004-1580
SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. • https://www.exploit-db.com/exploits/15278 http://marc.info/?l=bugtraq&m=109713382400457&w=2 http://secunia.com/advisories/12764 http://www.exploit-db.com/exploits/15278 http://www.securityfocus.com/bid/11337 https://exchange.xforce.ibmcloud.com/vulnerabilities/17632 •