CVE Vulnerabilities

CVE-2006-5109

Published: Oct 03, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Devellion CubeCart 2.0.x allows remote attackers to obtain sensitive information via a direct request for (1) link_navi.php or (2) spotlight.php, which reveals the path in various error messages. NOTE: the information.php, language.php, list_docs.php, popular_prod.php, sale.php, check_sum.php, and cat_navi.php vectors are already covered by CVE-2005-0607.

Affected Software

Name Vendor Start Version End Version
Cubecart Devellion 2.0.3 2.0.3
Cubecart Devellion 2.0.4 2.0.4
Cubecart Devellion 2.0.1 2.0.1
Cubecart Devellion 2.0.2 2.0.2
Cubecart Devellion 2.0.5 2.0.5
Cubecart Devellion 2.0.6 2.0.6
Cubecart Devellion 2.0.0 2.0.0

References