Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7) catId parameters in index.php; and the (8) username field in a login action in index.php. NOTE: the cart.php/redir and index.php/searchStr vectors are already covered by CVE-2005-3152.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Devellion | Cubecart | 3.0.7-pl1 |
References
- http://bugs.cubecart.com/?do=details&id=459ExploitVendor Advisory
- http://lostmon.blogspot.com/2006/01/cubecart-307-pl1-indexphp-multiple.htmlExploitVendor Advisory
- http://secunia.com/advisories/18519ExploitVendor Advisory
- http://www.osvdb.org/22471
- http://www.securityfocus.com/bid/16259Exploit
- http://www.vupen.com/english/advisories/2006/0227
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24177
- http://bugs.cubecart.com/?do=details&id=459ExploitVendor Advisory
- http://lostmon.blogspot.com/2006/01/cubecart-307-pl1-indexphp-multiple.htmlExploitVendor Advisory
- http://secunia.com/advisories/18519ExploitVendor Advisory
- http://www.osvdb.org/22471
- http://www.securityfocus.com/bid/16259Exploit
- http://www.vupen.com/english/advisories/2006/0227
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24177
FAQ
What is CVE-2006-0245?
CVE-2006-0245 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7) ca...
How severe is CVE-2006-0245?
CVE-2006-0245 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-0245?
Check the references section above for vendor advisories and patch information. Affected products include: Devellion Cubecart.