Vulnerabilities
Vulnerable Software
Cubecart:  >> Cubecart  >> 5.0.1  Security Vulnerabilities
Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
CVSS Score
6.8
EPSS Score
0.073
Published
2014-04-22
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.
CVSS Score
9.8
EPSS Score
0.31
Published
2013-02-08


Contact Us

Shodan ® - All rights reserved