CVE-2006-5108: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the orderid parameter in (1) admin/printorder.php and (2) vieworder.php; the (3) siteurl and (4) lasearchhome parameters and (5) certain language parameters in admin/nav.php; the (6) image parameter in admin/image.php; the (7) sitename, (8) laadmheader, (9) charset, and (10) certain other parameters in admin/header.inc.php; the (12) lapowby parameter in footer.inc.php; and the (13) sitename parameter and (14) certain other parameters in header.inc.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5108?
CVE-2006-5108 has been classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-5108?
To fix CVE-2006-5108, you should update your CubeCart to a version that is not affected by this vulnerability, specifically versions 2.0.7 or later.
What types of attacks can occur due to CVE-2006-5108?
CVE-2006-5108 allows attackers to perform cross-site scripting attacks, potentially leading to unauthorized access or control over user sessions.
Which versions of CubeCart are affected by CVE-2006-5108?
CVE-2006-5108 affects CubeCart versions 2.0.0 to 2.0.6.
How does CVE-2006-5108 impact users of CubeCart?
Users of affected CubeCart versions may be vulnerable to injection of arbitrary web scripts or HTML, compromising their security and data integrity.