CVE-2005-1033
CubeCart 2.0.6 - Information Disclosure via Error-Based Path Disclosure
Title source: llmExploitation Summary
EIP tracks 4 public exploits for CVE-2005-1033. PoCs published by John Cobb.
AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in CubeCart affecting multiple scripts due to improper input sanitization. It includes an example URL demonstrating the vulnerability but lacks executable exploit code.
Description
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.
Exploits (4)
The provided text describes SQL injection vulnerabilities in CubeCart affecting multiple scripts due to improper input sanitization. It includes an example URL demonstrating the vulnerability but lacks executable exploit code.
The provided text describes SQL injection vulnerabilities in CubeCart affecting multiple scripts due to improper input sanitization. It includes an example URL demonstrating the vulnerability but lacks executable exploit code.
The provided text describes SQL injection vulnerabilities in CubeCart affecting multiple scripts due to improper input sanitization. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.
The provided text describes SQL injection vulnerabilities in CubeCart due to improper input sanitization in multiple scripts. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.