PT-2005-2055 · Cubecart · Cubecart

John Cobb

·

Published

2005-04-09

·

Updated

2016-10-18

·

CVE-2005-1033

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CubeCart version 2.0.6
Description The issue allows remote attackers to obtain sensitive information via various invalid parameters to different PHP files, including the language parameter to "index.php", the PHPSESSID parameter to "index.php", the product parameter to "tellafriend.php", the add parameter to "view cart.php", or the product parameter to "view product.php". This reveals the path in a PHP error message.
Recommendations For CubeCart version 2.0.6, consider restricting access to the mentioned PHP files or validating the language, PHPSESSID, product, and add parameters to prevent the disclosure of sensitive information. As a temporary workaround, consider disabling the display of PHP error messages to minimize the risk of path disclosure.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1033

Affected Products

Cubecart