CVE-2006-0064: Code Injection
Published Jan 3, 2006
·Updated
PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter.
Affected Software
1 affected component
Devellion CubeCart
Event History
Jan 3, 2006
CVE Published
10:03 PM
Jan 4, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0064?
CVE-2006-0064 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2006-0064?
To fix CVE-2006-0064, upgrade to the latest version of CubeCart that includes the security patch.
3
What is the impact of CVE-2006-0064?
The impact of CVE-2006-0064 allows remote attackers to execute arbitrary PHP code, compromising the application and server.
4
Which versions of CubeCart are affected by CVE-2006-0064?
CVE-2006-0064 affects all versions of CubeCart prior to the patched releases addressing this vulnerability.
5
Is CVE-2006-0064 being actively exploited?
Yes, CVE-2006-0064 was known to be actively exploited shortly after its disclosure, posing a risk to vulnerable installations.