CVE-2005-0606
CubeCart 2.0.0-2.0.5 - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-0606. PoCs published by Lostmon.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in CubeCart by injecting malicious scripts into various URL parameters. These scripts execute in the context of the user's browser, potentially stealing cookies or performing other malicious actions.
Description
Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1) cat_id, (2) PHPSESSID, (3) view_doc, (4) product, (5) session, (6) catname, (7) search, or (8) page parameters.
Exploits (1)
The exploit demonstrates multiple XSS vulnerabilities in CubeCart by injecting malicious scripts into various URL parameters. These scripts execute in the context of the user's browser, potentially stealing cookies or performing other malicious actions.