CVE-2006-0245: XSS
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7) catId parameters in index.php; and the (8) username field in a login action in index.php. NOTE: the cart.php/redir and index.php/searchStr vectors are already covered by CVE-2005-3152.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0245?
CVE-2006-0245 is considered a moderate severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2006-0245?
To fix CVE-2006-0245, upgrade to a patched version of CubeCart that addresses these cross-site scripting vulnerabilities.
What are the affected parameters in CVE-2006-0245?
CVE-2006-0245 affects the parameters redir, productId, docId, act, catId, and the username field during login.
Who can exploit CVE-2006-0245?
CVE-2006-0245 can be exploited by remote attackers to inject arbitrary scripts into web pages viewed by users.
What software version is vulnerable in CVE-2006-0245?
The vulnerable version in CVE-2006-0245 is CubeCart 3.0.7-pl1.