MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) file, (2) x, and (3) y parameters in (a) admin/filemanager/preview.php; and the (4) email parameter in (b) admin/login.php
Published Aug 21, 2006
6.8
MEDIUMCVSS 2.0
EPSS 2.22%
Description
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) file, (2) x, and (3) y parameters in (a) admin/filemanager/preview.php; and the (4) email parameter in (b) admin/login.php.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (12)
- http://bugs.cubecart.com/?do=details&id=523 x_refsource_CONFIRM
- http://retrogod.altervista.org/cubecart_3011_adv.html x_refsource_MISCExploit
- http://secunia.com/advisories/21538 third-party-advisoryx_refsource_SECUNIAExploitPatchVendor Advisory
- http://securityreason.com/securityalert/1429 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1016708 vdb-entryx_refsource_SECTRACKExploit
- http://www.cubecart.com/site/forums/index.php?showtopic=21247 x_refsource_CONFIRM
- http://www.osvdb.org/27987 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/displayvuln.php?osvdb_id=27986 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/443476/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/19563 vdb-entryx_refsource_BIDExploit
- http://www.vupen.com/english/advisories/2006/3314 vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28429 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://bugs.cubecart.com/?do=details&id=523 | x_refsource_CONFIRM | |
| http://retrogod.altervista.org/cubecart_3011_adv.html | x_refsource_MISCExploit | |
| http://secunia.com/advisories/21538 | third-party-advisoryx_refsource_SECUNIAExploitPatchVendor Advisory | |
| http://securityreason.com/securityalert/1429 | third-party-advisoryx_refsource_SREASON | |
| http://securitytracker.com/id?1016708 | vdb-entryx_refsource_SECTRACKExploit | |
| http://www.cubecart.com/site/forums/index.php?showtopic=21247 | x_refsource_CONFIRM | |
| http://www.osvdb.org/27987 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/displayvuln.php?osvdb_id=27986 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/archive/1/443476/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/19563 | vdb-entryx_refsource_BIDExploit | |
| http://www.vupen.com/english/advisories/2006/3314 | vdb-entryx_refsource_VUPEN | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/28429 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 21, 2006
Updated Aug 7, 2024
Reserved Aug 21, 2006
Link CVE-2006-4268
CISA Vulnrichment
Updated n/a