Lucene search

K
cveMitreCVE-2005-1033
HistoryMay 02, 2005 - 4:00 a.m.

CVE-2005-1033

2005-05-0204:00:00
mitre
web.nvd.nist.gov
42
cubecart
security vulnerability
remote attackers
sensitive information
php error
cve-2005-1033

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.027

Percentile

90.6%

CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.

Affected configurations

Nvd
Node
devellioncubecartMatch2.0.6
VendorProductVersionCPE
devellioncubecart2.0.6cpe:2.3:a:devellion:cubecart:2.0.6:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.027

Percentile

90.6%

Related for CVE-2005-1033