Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2017-2090

Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-6928

Disclosure Date: September 28, 2015 (last updated October 05, 2023)
classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the email parameter.
0
Attacker Value
Unknown

CVE-2014-2341

Disclosure Date: April 22, 2014 (last updated October 05, 2023)
Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
0
Attacker Value
Unknown

CVE-2013-1465

Disclosure Date: February 08, 2013 (last updated January 09, 2024)
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.
Attacker Value
Unknown

CVE-2012-0865

Disclosure Date: February 21, 2012 (last updated October 04, 2023)
Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) r parameter to switch.php or (2) goto parameter to admin/login.php.
0
Attacker Value
Unknown

CVE-2010-4903

Disclosure Date: October 08, 2011 (last updated October 04, 2023)
SQL injection vulnerability in index.php in CubeCart 4.3.3 allows remote attackers to execute arbitrary SQL commands via the searchStr parameter.
0
Attacker Value
Unknown

CVE-2011-3724

Disclosure Date: September 23, 2011 (last updated October 04, 2023)
CubeCart 4.4.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/shipping/USPS/calc.php and certain other files.
0
Attacker Value
Unknown

CVE-2010-1931

Disclosure Date: June 10, 2010 (last updated October 04, 2023)
SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arbitrary SQL commands via the shipKey parameter to index.php.
0
Attacker Value
Unknown

CVE-2009-4060

Disclosure Date: November 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter.
0
Attacker Value
Unknown

CVE-2009-3904

Disclosure Date: November 06, 2009 (last updated October 04, 2023)
classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to bypass restrictions and gain administrative access via a HTTP request that contains an empty (1) sessID (ccAdmin cookie), (2) X_CLUSTER_CLIENT_IP header, or (3) User-Agent header.
0