First published: Fri Feb 08 2013(Updated: )
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
>=5.0.0<=5.2.0 | ||
Cubecart Cubecart | =5.0.0 | |
Cubecart Cubecart | =5.0.1 | |
Cubecart Cubecart | =5.0.2 | |
Cubecart Cubecart | =5.0.3 | |
Cubecart Cubecart | =5.0.4 | |
Cubecart Cubecart | =5.0.5 | |
Cubecart Cubecart | =5.0.6 | |
Cubecart Cubecart | =5.0.7 | |
Cubecart Cubecart | =5.0.8 | |
Cubecart Cubecart | =5.0.9 | |
Cubecart Cubecart | =5.1.0 | |
Cubecart Cubecart | =5.1.1 | |
Cubecart Cubecart | =5.1.2 | |
Cubecart Cubecart | =5.1.3 | |
Cubecart Cubecart | =5.1.4 | |
Cubecart Cubecart | =5.1.5 | |
Cubecart Cubecart | =5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-1465 is considered high due to the potential for remote code execution through object injection.
To fix CVE-2013-1465, upgrade CubeCart to version 5.2.1 or later, where the vulnerability has been patched.
CVE-2013-1465 affects CubeCart versions from 5.0.0 to 5.2.0, inclusive.
CVE-2013-1465 can be exploited through crafted shipping parameters to unserialize arbitrary PHP objects.
Yes, CVE-2013-1465 is a remote vulnerability that allows attackers to exploit the CubeCart application without physical access.