CVE-2005-0443: XSS
Published Feb 15, 2005
·Updated
index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message.
Affected Software
2 affected components
Devellion CubeCart=2.0.4
Devellion CubeCart=2.0.1
Remediation
Patch Available
Patch Available
Event History
Feb 15, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0443?
CVE-2005-0443 has a medium severity level due to its potential for information disclosure and cross-site scripting.
2
How do I fix CVE-2005-0443?
To fix CVE-2005-0443, upgrade CubeCart to version 2.0.5 or later as this version addresses the vulnerability.
3
What types of attacks are possible with CVE-2005-0443?
CVE-2005-0443 allows for remote attackers to conduct information disclosure and cross-site scripting (XSS) attacks.
4
Which versions of CubeCart are affected by CVE-2005-0443?
CVE-2005-0443 affects CubeCart versions 2.0.1 and 2.0.4.
5
Can CVE-2005-0443 lead to full path disclosure?
Yes, CVE-2005-0443 can lead to full path disclosure through an invalid language parameter in the index.php file.