CubeCart Multiple Security Vulnerabilities
BID:19782
CVE-2006-4525 | CVE-2006-4526 | CVE-2006-4527 |Info
CubeCart Multiple Security Vulnerabilities
| Bugtraq ID: | 19782 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 31 2006 12:00AM |
| Updated: | Sep 05 2006 04:08PM |
| Credit: | GulfTech Research and Development is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
CubeCart CubeCart 3.0.12 |
| Not Vulnerable: | |
Discussion
CubeCart Multiple Security Vulnerabilities
CubeCart is prone to multiple security vulnerabilities, including cross-site scripting, remote file inclusion, and a SQL-injection issue, because the application fails to properly sanitize user-supplied input. The vendor has released updates that address these vulnerabilities.
A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
CubeCart 3.0.12 is vulnerable to these issues; other versions may also be affected.
CubeCart is prone to multiple security vulnerabilities, including cross-site scripting, remote file inclusion, and a SQL-injection issue, because the application fails to properly sanitize user-supplied input. The vendor has released updates that address these vulnerabilities.
A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
CubeCart 3.0.12 is vulnerable to these issues; other versions may also be affected.
Exploit / POC
CubeCart Multiple Security Vulnerabilities
Attackers can exploit these issues via a web client.
Attackers can exploit these issues via a web client.
Solution / Fix
CubeCart Multiple Security Vulnerabilities
Solution:
The vendor has released a patch and configuration instructions to address these issues. Please see the referenced vendor advisory for more information.
Solution:
The vendor has released a patch and configuration instructions to address these issues. Please see the referenced vendor advisory for more information.
References
CubeCart Multiple Security Vulnerabilities
References:
References:
- CubeCart Multiple Vulnerabilities (GulfTech Research and Development)
- Security Patch 28th August 2006, , All must apply this patch (Cube Cart)