Skip to main content

Vendor/product archive

devellion / cubecart CVEs

Beta · best-effort

21 CVEs tagged to devellion / cubecart0 Critical, 6 High, 14 Medium, 1 Low, 0 Unrated.

CVE-2007-2862

Published May 24, 2007

Multiple SQL injection vulnerabilities in CubeCart 3.0.16 might allow remote attackers to execute arbitrary SQL commands via an unspecified parameter to cart.inc.php and certain o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2550

Published May 9, 2007

Multiple CRLF injection vulnerabilities in Devellion CubeCart 3.0.15 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5107

Published Oct 3, 2006

Multiple SQL injection vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter in admin/forgot_pass.ph…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5108

Published Oct 3, 2006

Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the order_id parameter in (1) adm…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5109

Published Oct 3, 2006

Devellion CubeCart 2.0.x allows remote attackers to obtain sensitive information via a direct request for (1) link_navi.php or (2) spotlight.php, which reveals the path in various…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4525

Published Sep 1, 2006

Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the l…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4526

Published Sep 1, 2006

SQL injection vulnerability in includes/content/viewCat.inc.php in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary SQL…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4527

Published Sep 1, 2006

includes/content/gateway.inc.php in CubeCart 3.0.12 and earlier, when magic_quotes_gpc is disabled, uses an insufficiently restrictive regular expression to validate the gateway p…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4267

Published Aug 21, 2006

Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) oid parameter in modules/gateway/Protx/c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4268

Published Aug 21, 2006

Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) file, (2) x, and (3) y…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0922

Published Feb 28, 2006

CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0245

Published Jan 18, 2006

Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0064

Published Jan 3, 2006

PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3152

Published Oct 5, 2005

Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir parameter to (1) cart.php or (2)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0442

Published May 2, 2005

Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0443

Published May 2, 2005

index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parame…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0606

Published May 2, 2005

Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0607

Published May 2, 2005

CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) lis…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1033

Published May 2, 2005

CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parame…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1579

Published Dec 31, 2004

index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1580

Published Dec 31, 2004

SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1