CVE-2005-0607: Medium severity Devellion CubeCart vulnerability
CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) listdocs.php, (4) popularprod.php, (5) sale.php, (6) subfooter.inc.php, (7) subheader.inc.php, (8) catnavi.php, or (9) checksum.php, which reveals the path in a PHP error message.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0607?
CVE-2005-0607 is considered a medium severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2005-0607?
To fix CVE-2005-0607, upgrade CubeCart to version 2.0.6 or later.
What is the impact of CVE-2005-0607?
CVE-2005-0607 allows remote attackers to disclose the server's full path, potentially aiding in further attacks.
Which versions of CubeCart are affected by CVE-2005-0607?
CubeCart versions 2.0.0 through 2.0.5 are affected by CVE-2005-0607.
Can CVE-2005-0607 be exploited without authentication?
Yes, CVE-2005-0607 can be exploited by unauthenticated remote attackers.