CVE Vulnerabilities

CVE-2006-4268

Published: Aug 21, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) file, (2) x, and (3) y parameters in (a) admin/filemanager/preview.php; and the (4) email parameter in (b) admin/login.php.

Affected Software

Name Vendor Start Version End Version
Cubecart Devellion 3.0.3 (including) 3.0.3 (including)
Cubecart Devellion 3.0.4 (including) 3.0.4 (including)
Cubecart Devellion 3.0.6 (including) 3.0.6 (including)
Cubecart Devellion 3.0.7 (including) 3.0.7 (including)
Cubecart Devellion 3.0.7-pl1 (including) 3.0.7-pl1 (including)
Cubecart Devellion 3.0.11 (including) 3.0.11 (including)

References