7.5

CVE-2006-4267

Exploit

Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) oid parameter in modules/gateway/Protx/confirmed.php and the (2) x_invoice_num parameter in modules/gateway/Authorize/confirmed.php.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DevellionCubecart Version3.0.3
DevellionCubecart Version3.0.4
DevellionCubecart Version3.0.6
DevellionCubecart Version3.0.7
DevellionCubecart Version3.0.7-pl1
DevellionCubecart Version3.0.11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.14% 0.864
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P