PT-2009-6126 · Cubecart · Cubecart

Published

2009-11-06

·

Updated

2018-10-10

·

CVE-2009-3904

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CubeCart version 4.3.4
Description The issue allows remote attackers to bypass administrative access restrictions and gain administrative access. This can be achieved via a HTTP request that contains an empty sessID (ccAdmin cookie), X CLUSTER CLIENT IP header, or User-Agent header.
Recommendations For CubeCart version 4.3.4, update the classes/session/cc admin session.php file to properly restrict administrative access permissions, ensuring that empty or missing headers and cookies do not allow unauthorized access. As a temporary workaround, consider restricting access to administrative functions until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3904

Affected Products

Cubecart