includes/content/gateway.inc.php in CubeCart 3.0.12 and earlier, when magic_quotes_gpc is disabled, uses an insufficiently restrictive regular expression to validate the gateway parameter, which allows remote attackers to conduct PHP remote file inclusion attacks.
References
Configurations
History
21 Nov 2024, 00:16
Type | Values Removed | Values Added |
---|---|---|
References | () http://cubecart.com/site/forums/index.php?showtopic=21540 - | |
References | () http://secunia.com/advisories/21659 - Vendor Advisory | |
References | () http://www.cubecart.com/site/forums/index.php?s=5e34938dc670782af211587b8a450c90&act=Attach&type=post&id=697 - | |
References | () http://www.gulftech.org/?node=research&article_id=00111-08282006& - | |
References | () http://www.securityfocus.com/bid/19782 - |
Information
Published : 2006-09-01 23:04
Updated : 2025-04-03 01:03
NVD link : CVE-2006-4527
Mitre link : CVE-2006-4527
CVE.ORG link : CVE-2006-4527
JSON object : View
Products Affected
devellion
- cubecart
CWE