Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.15442
Category:CGI abuses
Title:CubeCart SQL injection
Summary:NOSUMMARY
Description:Description:

The remote host is running Brooky CubeCart, an online store application
written in PHP.

There is a SQL injection issue in the remote version of this software which
may allow an attacker to execute arbitrary SQL statements on the remote host
and to potentially overwrite arbitrary files on the remote system, by
sending a malformed value to the 'cat_id' argument of the file 'index.php'.

Solution : Upgrade to the latest version of this software
Risk factor : High

Cross-Ref: BugTraq ID: 11337
Common Vulnerability Exposure (CVE) ID: CVE-2004-1580
http://www.securityfocus.com/bid/11337
Bugtraq: 20041006 Full path disclosure and sql injection on CubeCart 2.0.1 (Google Search)
http://marc.info/?l=bugtraq&m=109713382400457&w=2
http://www.exploit-db.com/exploits/15278
http://secunia.com/advisories/12764
XForce ISS Database: cubecart-catid-sql-injection(17632)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17632
CopyrightThis script is Copyright (C) 2004 Tenable Network Security

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.