PoC Index

CVE-2005-0606

MEDIUM 4.3EPSS 2.0%

Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1) cat_id, (2) PHPSESSID, (3) view_doc, (4) product, (5) session, (6) catname, (7) search, or (8) page parameters.

CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.96% chance of exploitation in the next 30 days, 79th percentile
Published
2005-03-01
Updated
2024-08-07

ExploitDB entries (1)

References

Related