Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown
CVE-2024-34832
Disclosure Date: June 06, 2024 (last updated August 03, 2024)
Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.
0
Attacker Value
Unknown
CVE-2023-47675
Disclosure Date: November 17, 2023 (last updated November 22, 2023)
CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command.
0
Attacker Value
Unknown
CVE-2023-47283
Disclosure Date: November 17, 2023 (last updated November 22, 2023)
Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to obtain files in the system.
0
Attacker Value
Unknown
CVE-2023-42428
Disclosure Date: November 17, 2023 (last updated November 22, 2023)
Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete directories and files in the system.
0
Attacker Value
Unknown
CVE-2023-38130
Disclosure Date: November 17, 2023 (last updated November 22, 2023)
Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system.
0
Attacker Value
Unknown
CVE-2021-33394
Disclosure Date: May 27, 2021 (last updated February 22, 2025)
Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in, the injected cookie becomes valid, giving the attacker access to the user's account through the active session.
0
Attacker Value
Unknown
CVE-2018-20716
Disclosure Date: January 15, 2019 (last updated November 27, 2024)
CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
0
Attacker Value
Unknown
CVE-2018-20703
Disclosure Date: January 13, 2019 (last updated November 27, 2024)
CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string.
0
Attacker Value
Unknown
CVE-2017-2098
Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-2117
Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in CubeCart versions prior to 6.1.5 allows attacker with administrator rights to read arbitrary files via unspecified vectors.
0