CVE-2009-3904: High severity cubecart vulnerability
classes/session/ccadminsession.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to bypass restrictions and gain administrative access via a HTTP request that contains an empty (1) sessID (ccAdmin cookie), (2) XCLUSTERCLIENTIP header, or (3) User-Agent header.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3904?
CVE-2009-3904 is classified as a medium severity vulnerability due to the potential for unauthorized administrative access.
How do I fix CVE-2009-3904?
To mitigate CVE-2009-3904, upgrade CubeCart to a version higher than 4.3.4, which addresses the access permissions vulnerability.
What type of vulnerability is CVE-2009-3904?
CVE-2009-3904 is an access control vulnerability that allows remote attackers to gain unauthorized administrative access.
Which versions of CubeCart are affected by CVE-2009-3904?
CVE-2009-3904 specifically affects CubeCart version 4.3.4.
What are the consequences of exploiting CVE-2009-3904?
Exploiting CVE-2009-3904 can allow attackers to bypass administrative access controls, potentially compromising the entire CubeCart installation.