CVE-2006-4268: XSS
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) file, (2) x, and (3) y parameters in (a) admin/filemanager/preview.php; and the (4) email parameter in (b) admin/login.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4268?
CVE-2006-4268 is a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-4268?
To fix CVE-2006-4268, upgrade CubeCart to version 3.0.12 or later, which addresses these XSS vulnerabilities.
Which versions of CubeCart are affected by CVE-2006-4268?
CVE-2006-4268 affects CubeCart versions 3.0.3, 3.0.4, 3.0.6, 3.0.7, and 3.0.11.
What are the primary vulnerabilities in CVE-2006-4268?
CVE-2006-4268 allows remote attackers to inject arbitrary web scripts or HTML through specific parameters in the file manager and login sections.
Can CVE-2006-4268 lead to data theft?
Yes, if exploited, CVE-2006-4268 can allow attackers to steal sensitive user data through cross-site scripting.