First published: Fri Nov 06 2009(Updated: )
classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to bypass restrictions and gain administrative access via a HTTP request that contains an empty (1) sessID (ccAdmin cookie), (2) X_CLUSTER_CLIENT_IP header, or (3) User-Agent header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cubecart Cubecart | =4.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3904 is classified as a medium severity vulnerability due to the potential for unauthorized administrative access.
To mitigate CVE-2009-3904, upgrade CubeCart to a version higher than 4.3.4, which addresses the access permissions vulnerability.
CVE-2009-3904 is an access control vulnerability that allows remote attackers to gain unauthorized administrative access.
CVE-2009-3904 specifically affects CubeCart version 4.3.4.
Exploiting CVE-2009-3904 can allow attackers to bypass administrative access controls, potentially compromising the entire CubeCart installation.