Vulnerabilities > CVE-2006-0922 - Unspecified vulnerability in Devellion Cubecart
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to upload arbitrary files via a modified CurrentFolder parameter in a direct request to admin/filemanager/upload.php.
Vulnerable Configurations
Exploit-Db
description | CubeCart 3.0.x Arbitrary File Upload Vulnerability. CVE-2006-0922. Webapps exploit for php platform |
id | EDB-ID:27304 |
last seen | 2016-02-03 |
modified | 2006-02-23 |
published | 2006-02-23 |
reporter | NSA Group |
source | https://www.exploit-db.com/download/27304/ |
title | CubeCart 3.0.x - Arbitrary File Upload Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | CUBECART_FCKEDITOR_UPLOAD.NASL |
description | The version of CubeCart installed on the remote host allows an unauthenticated user to upload files with arbitrary PHP code and then to execute them subject to the privileges of the web server user id. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21187 |
published | 2006-04-05 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21187 |
title | CubeCart FCKeditor connector.php Arbitrary File Upload |
code |
|
References
- http://securityreason.com/securityalert/482
- http://securityreason.com/securityalert/482
- http://www.cubecart.com/site/forums/index.php?showtopic=14704
- http://www.cubecart.com/site/forums/index.php?showtopic=14704
- http://www.cubecart.com/site/forums/index.php?showtopic=14817
- http://www.cubecart.com/site/forums/index.php?showtopic=14817
- http://www.cubecart.com/site/forums/index.php?showtopic=14825
- http://www.cubecart.com/site/forums/index.php?showtopic=14825
- http://www.cubecart.com/site/forums/index.php?showtopic=14960
- http://www.cubecart.com/site/forums/index.php?showtopic=14960
- http://www.cubecart.com/site/forums/index.php?showtopic=14972
- http://www.cubecart.com/site/forums/index.php?showtopic=14972
- http://www.nsag.ru/vuln/892.html
- http://www.nsag.ru/vuln/892.html
- http://www.securityfocus.com/archive/1/425931/100/0/threaded
- http://www.securityfocus.com/archive/1/425931/100/0/threaded
- http://www.securityfocus.com/bid/16796
- http://www.securityfocus.com/bid/16796
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24883
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24883