Cubecart Cubecart 5.0.5

CPE Details

Cubecart Cubecart 5.0.5
5.0.5
2023-10-27
11h50 +00:00
2023-10-27
11h50 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:cubecart:cubecart:5.0.5:*:*:*:*:*:*:*

Informations

Vendor

cubecart

Product

cubecart

Version

5.0.5

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-34832 2024-06-06 14h45 +00:00 Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.
9.8
Critique
CVE-2023-47675 2023-11-17 04h37 +00:00 CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command.
7.2
Haute
CVE-2023-47283 2023-11-17 04h37 +00:00 Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to obtain files in the system.
4.9
Moyen
CVE-2023-42428 2023-11-17 04h37 +00:00 Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete directories and files in the system.
6.5
Moyen
CVE-2023-38130 2023-11-17 04h37 +00:00 Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system.
8.1
Haute
CVE-2018-20716 2019-01-15 15h00 +00:00 CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
9.8
Critique
CVE-2017-2090 2017-04-28 14h00 +00:00 Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
6.5
Moyen
CVE-2017-2098 2017-04-28 14h00 +00:00 Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
6.5
Moyen
CVE-2017-2117 2017-04-28 14h00 +00:00 Directory traversal vulnerability in CubeCart versions prior to 6.1.5 allows attacker with administrator rights to read arbitrary files via unspecified vectors.
4.9
Moyen
CVE-2014-2341 2014-04-21 12h00 +00:00 Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
6.8
CVE-2013-1465 2013-02-08 19h00 +00:00 The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.
9.8
Critique