Vulnerabilities > Devellion > Cubecart > 2.0.4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-10-03 | CVE-2006-5109 | Input Validation vulnerability in CubeCart Devellion CubeCart 2.0.x allows remote attackers to obtain sensitive information via a direct request for (1) link_navi.php or (2) spotlight.php, which reveals the path in various error messages. | 5.0 |
2006-10-03 | CVE-2006-5108 | Input Validation vulnerability in CubeCart Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the order_id parameter in (1) admin/print_order.php and (2) view_order.php; the (3) site_url and (4) la_search_home parameters and (5) certain language parameters in admin/nav.php; the (6) image parameter in admin/image.php; the (7) site_name, (8) la_adm_header, (9) charset, and (10) certain other parameters in admin/header.inc.php; the (12) la_pow_by parameter in footer.inc.php; and the (13) site_name parameter and (14) certain other parameters in header.inc.php. network devellion | 6.8 |
2006-10-03 | CVE-2006-5107 | Input Validation vulnerability in CubeCart Multiple SQL injection vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter in admin/forgot_pass.php, (2) the order_id parameter in view_order.php, (3) the view_doc parameter in view_doc.php, and (4) the order_id parameter in admin/print_order.php. | 7.5 |
2005-05-02 | CVE-2005-0443 | Multiple vulnerability in Brooky Cubecart 2.0.1/2.0.4 index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message. network devellion | 4.3 |
2005-05-02 | CVE-2005-0442 | Multiple vulnerability in Brooky Cubecart 2.0.1/2.0.4 Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter. | 5.0 |