CVE-2006-4525: XSS
Published Sep 1, 2006
·Updated
Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when registerglobals is enabled, allows remote attackers to inject arbitrary web script or HTML via the links array.
Affected Software
1 affected component
Devellion CubeCart<=3.0.12
Event History
Sep 1, 2006
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4525?
CVE-2006-4525 has a high severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2006-4525?
To fix CVE-2006-4525, disable register_globals and upgrade to a version of CubeCart later than 3.0.12.
3
What software does CVE-2006-4525 affect?
CVE-2006-4525 affects CubeCart versions 3.0.12 and earlier.
4
What type of vulnerability is CVE-2006-4525?
CVE-2006-4525 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2006-4525 lead to remote attacks?
Yes, CVE-2006-4525 allows remote attackers to inject arbitrary web scripts or HTML.