Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2007-2862 Multiple SQL injection vulnerabilities in CubeCart 3.0.16 might allow remote attackers to execute arbitrary SQL commands via an unspecified parameter… Cubecart Mitigation only Fix from $1,9502007-05-24 MEDIUM 5.0 CVE-2007-2550 Multiple CRLF injection vulnerabilities in Devellion CubeCart 3.0.15 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP respons… Cubecart Mitigation only Fix from $1,6002007-05-09 HIGH 7.5 CVE-2006-5107 Multiple SQL injection vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to execute arbitrary SQL commands via (1) the user_name par… Cubecart No fix yet Fix from $1,9502006-10-03 MEDIUM 6.8 CVE-2006-5108EPSS 6% Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the… Cubecart No fix yet Fix from $1,6002006-10-03 MEDIUM 5.0 CVE-2006-5109 Devellion CubeCart 2.0.x allows remote attackers to obtain sensitive information via a direct request for (1) link_navi.php or (2) spotlight.php, whi… Cubecart No fix yet Fix from $1,6002006-10-03 HIGH 7.5 CVE-2006-4526 SQL injection vulnerability in includes/content/viewCat.inc.php in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attac… Cubecart after 3.0.12 Fix from $1,9502006-09-01 HIGH 7.5 CVE-2006-4267 Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) oid parame… Cubecart Patch available Fix from $1,9502006-08-21 MEDIUM 6.8 CVE-2006-4268 Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via … Cubecart Patch available Fix from $1,6002006-08-21 MEDIUM 5.0 CVE-2006-0922EPSS 8% CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results… Cubecart Patch available Fix from $1,6002006-02-28 HIGH 7.5 CVE-2006-0064 PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in… Cubecart No fix yet Fix from $1,9502006-01-03 MEDIUM 5.0 CVE-2005-0442EPSS 8% Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter. Cubecart Patch available Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-0607 CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.… Cubecart Patch available Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-1033 CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to… Cubecart Mitigation only Fix from $1,6002005-05-02 HIGH 7.5 CVE-2004-1580 SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. Cubecart Patch available Fix from $1,9502004-12-31 MEDIUM 5.0 CVE-2004-1579 index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals… Cubecart Mitigation only Fix from $1,6002004-12-31