CVE-2006-4267: SQL Injection
Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) oid parameter in modules/gateway/Protx/confirmed.php and the (2) xinvoicenum parameter in modules/gateway/Authorize/confirmed.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4267?
CVE-2006-4267 is classified as a high severity vulnerability due to its ability to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2006-4267?
To fix CVE-2006-4267, upgrade CubeCart to version 3.0.12 or later where this vulnerability is addressed.
Which versions of CubeCart are affected by CVE-2006-4267?
CVE-2006-4267 affects CubeCart versions 3.0.3, 3.0.4, 3.0.6, 3.0.7, 3.0.7-pl1, and 3.0.11.
What are the common attack vectors for CVE-2006-4267?
Attackers can exploit CVE-2006-4267 via the 'oid' parameter in modules/gateway/Protx/confirmed.php and the 'x_invoice_num' parameter in modules/gateway/Authorize/confirmed.php.
Is CVE-2006-4267 easy to exploit?
Yes, CVE-2006-4267 is considered relatively easy to exploit, making it a significant threat to affected installations.