Vulnerabilities > CVE-2005-0442 - Multiple vulnerability in Brooky Cubecart 2.0.1/2.0.4

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
devellion
nessus
exploit available

Summary

Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter.

Vulnerable Configurations

Part Description Count
Application
Devellion
2

Exploit-Db

descriptionBrooky CubeCart 2.0.1/2.0.4 index.php language Parameter Traversal Arbitrary File Access. CVE-2005-0442. Webapps exploit for php platform
idEDB-ID:25098
last seen2016-02-03
modified2005-02-14
published2005-02-14
reporterJohn Cobb
sourcehttps://www.exploit-db.com/download/25098/
titleBrooky CubeCart 2.0.1/2.0.4 index.php language Parameter Traversal Arbitrary File Access

Nessus

NASL familyCGI abuses
NASL idCUBECART_LANG_XSS.NASL
descriptionThe version of CubeCart on the remote host is vulnerable to a local file include issue, along with related cross-site scripting and path disclosure issues, due to a failure to sanitize user-supplied data. Successful exploitation of this issue may allow an attacker to execute arbitrary code on the remote host, to read arbitrary files from it, to inject arbitrary HTML or script code through the affected application and into a user
last seen2020-06-01
modified2020-06-02
plugin id17227
published2005-02-28
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/17227
titleCubeCart < 2.0.5 Multiple Vulnerabilities