Known Vulnerabilities for products from Devellion
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Devellion".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2007-2862 json | Multiple SQL injection vulnerabilities in CubeCart 3.0.16 might allow remote attackers to execute arbitrary SQL commands via ... | Not Provided | 2007-05-24 | 2026-04-23 |
| CVE-2007-2550 json | Multiple CRLF injection vulnerabilities in Devellion CubeCart 3.0.15 allow remote attackers to inject arbitrary HTTP headers ... | Not Provided | 2007-05-09 | 2026-04-23 |
| CVE-2006-5109 json | Devellion CubeCart 2.0.x allows remote attackers to obtain sensitive information via a direct request for (1) link_navi.php o... | Not Provided | 2006-10-03 | 2026-04-23 |
| CVE-2006-5108 json | Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary we... | Not Provided | 2006-10-03 | 2026-04-23 |
| CVE-2006-5107 json | Multiple SQL injection vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to execute arbitrary SQL commands v... | Not Provided | 2006-10-03 | 2026-04-23 |
| CVE-2006-4527 json | includes/content/gateway.inc.php in CubeCart 3.0.12 and earlier, when magic_quotes_gpc is disabled, uses an insufficiently re... | 2.6 - LOW | 2006-09-01 | 2008-09-05 |
| CVE-2006-4526 json | SQL injection vulnerability in includes/content/viewCat.inc.php in CubeCart 3.0.12 and earlier, when register_globals is enab... | 7.5 - HIGH | 2006-09-01 | 2008-09-05 |
| CVE-2006-4525 json | Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote atta... | 4.3 - MEDIUM | 2006-09-01 | 2008-09-05 |
| CVE-2006-4268 json | Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to inject arbitrary... | 6.8 - MEDIUM | 2006-08-21 | 2018-10-17 |
| CVE-2006-4267 json | Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL command... | 7.5 - HIGH | 2006-08-21 | 2018-10-17 |
| CVE-2006-0922 json | CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.ph... | Not Provided | 2006-02-28 | 2025-04-03 |
| CVE-2006-0245 json | Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web scri... | Not Provided | 2006-01-18 | 2025-04-03 |
| CVE-2006-0064 json | PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitra... | Not Provided | 2006-01-03 | 2025-04-03 |
| CVE-2005-3152 json | Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script o... | Not Provided | 2005-10-05 | 2025-04-03 |
| CVE-2005-1033 json | CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2... | Not Provided | 2005-05-02 | 2025-04-03 |
| CVE-2005-0607 json | CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parame... | Not Provided | 2005-05-02 | 2025-04-03 |
| CVE-2005-0606 json | Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files,... | Not Provided | 2005-05-02 | 2025-04-03 |
| CVE-2005-0443 json | index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site ... | Not Provided | 2005-05-02 | 2025-04-03 |
| CVE-2005-0442 json | Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the lan... | Not Provided | 2005-05-02 | 2025-04-03 |
| CVE-2004-1580 json | SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the ... | Not Provided | 2004-12-31 | 2025-04-03 |