Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Sangte Amtham

#34936de 53,639
7.5CVSS total
Vulnerabilidades · 1
PT-2009-6241
7.5
2009-11-24
Cubecart · Cubecart · CVE-2009-4060
**Name of the Vulnerable Software and Affected Versions** CubeCart versions prior to 4.3.7 **Description** The issue allows remote attackers to execute arbitrary SQL commands via the `productId` parameter in the includes/content/viewProd.inc.php file. **Recommendations** For versions prior to 4.3.7, update to version 4.3.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the `viewProd.inc.php` file or avoiding the use of the `productId` parameter in the affected API endpoint until the issue is resolved.