PT-2005-1504 · Cubecart · Cubecart
John Cobb
·
Published
2005-02-15
·
Updated
2017-07-11
·
CVE-2005-0443
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CubeCart version 2.0.4
Description
The issue allows remote attackers to either obtain the full path for the web server or conduct cross-site scripting (XSS) attacks. This is achieved via an invalid language parameter in index.php, which echoes the parameter in a PHP error message, potentially leading to XSS attacks or information disclosure.
Recommendations
For CubeCart version 2.0.4, consider validating and sanitizing the language parameter to prevent echoing of invalid input, and restrict access to error messages that could disclose sensitive information. As a temporary workaround, consider disabling the language parameter functionality in index.php until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cubecart