PT-2005-1504 · Cubecart · Cubecart

John Cobb

·

Published

2005-02-15

·

Updated

2017-07-11

·

CVE-2005-0443

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CubeCart version 2.0.4
Description The issue allows remote attackers to either obtain the full path for the web server or conduct cross-site scripting (XSS) attacks. This is achieved via an invalid language parameter in index.php, which echoes the parameter in a PHP error message, potentially leading to XSS attacks or information disclosure.
Recommendations For CubeCart version 2.0.4, consider validating and sanitizing the language parameter to prevent echoing of invalid input, and restrict access to error messages that could disclose sensitive information. As a temporary workaround, consider disabling the language parameter functionality in index.php until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0443

Affected Products

Cubecart