Vulnerabilities
Vulnerable Software
Cubecart:  >> Cubecart  >> 5.1.1  Security Vulnerabilities
CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
CVSS Score
9.8
EPSS Score
0.003
Published
2019-01-15
Directory traversal vulnerability in CubeCart versions prior to 6.1.5 allows attacker with administrator rights to read arbitrary files via unspecified vectors.
CVSS Score
4.9
EPSS Score
0.017
Published
2017-04-28
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
CVSS Score
6.5
EPSS Score
0.034
Published
2017-04-28
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
CVSS Score
6.5
EPSS Score
0.015
Published
2017-04-28
Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
CVSS Score
6.8
EPSS Score
0.073
Published
2014-04-22
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.
CVSS Score
9.8
EPSS Score
0.31
Published
2013-02-08


Contact Us

Shodan ® - All rights reserved