Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-0865

Опубликовано: 21 фев. 2012
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) r parameter to switch.php or (2) goto parameter to admin/login.php.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cubecart:cubecart:*:*:*:*:*:*:*:*
Версия до 3.0.20 (включая)
cpe:2.3:a:cubecart:cubecart:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.7:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.8:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.9:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.10:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.11:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.12:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.13:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.14:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.15:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.16:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.17:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.18:*:*:*:*:*:*:*
cpe:2.3:a:cubecart:cubecart:3.0.19:*:*:*:*:*:*:*

EPSS

Процентиль: 91%
0.06224
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
больше 3 лет назад

Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) r parameter to switch.php or (2) goto parameter to admin/login.php.

EPSS

Процентиль: 91%
0.06224
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-20