Vulnerabilities > CVE-2005-0443 - Multiple vulnerability in Brooky Cubecart 2.0.1/2.0.4

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
devellion
nessus
exploit available

Summary

index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message.

Vulnerable Configurations

Part Description Count
Application
Devellion
2

Exploit-Db

descriptionBrooky CubeCart 2.0.1/2.0.4 ndex.php language Parameter XSS. CVE-2005-0443. Webapps exploit for php platform
idEDB-ID:25097
last seen2016-02-03
modified2005-02-14
published2005-02-14
reporterJohn Cobb
sourcehttps://www.exploit-db.com/download/25097/
titleBrooky CubeCart 2.0.1/2.0.4 ndex.php language Parameter XSS

Nessus

NASL familyCGI abuses
NASL idCUBECART_LANG_XSS.NASL
descriptionThe version of CubeCart on the remote host is vulnerable to a local file include issue, along with related cross-site scripting and path disclosure issues, due to a failure to sanitize user-supplied data. Successful exploitation of this issue may allow an attacker to execute arbitrary code on the remote host, to read arbitrary files from it, to inject arbitrary HTML or script code through the affected application and into a user
last seen2020-06-01
modified2020-06-02
plugin id17227
published2005-02-28
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/17227
titleCubeCart < 2.0.5 Multiple Vulnerabilities