CVE-2005-0606: XSS
Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1) catid, (2) PHPSESSID, (3) viewdoc, (4) product, (5) session, (6) catname, (7) search, or (8) page parameters.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0606?
CVE-2005-0606 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2005-0606?
To fix CVE-2005-0606, upgrade CubeCart to version 2.0.6 or later.
What is the impact of CVE-2005-0606?
The impact of CVE-2005-0606 allows attackers to inject arbitrary HTML or web scripts into CubeCart.
Which versions of CubeCart are affected by CVE-2005-0606?
CubeCart versions 2.0.0 through 2.0.5 are affected by CVE-2005-0606.
How can I identify if my system is vulnerable to CVE-2005-0606?
You can identify if your system is vulnerable to CVE-2005-0606 by checking if you are using CubeCart version 2.0.0 to 2.0.5.