CVE-2012-0865

CubeCart < 3.0.20 - Open Redirect via switch.php r Parameter or admin/login.php goto Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2012-0865. PoCs published by Aung Khant.

AI-analyzed exploit summary The exploit describes a URI-redirection vulnerability in CubeCart due to improper input sanitization. It provides example URLs demonstrating how an attacker could redirect users to malicious sites via the 'redir' parameter.

Description

Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) r parameter to switch.php or (2) goto parameter to admin/login.php.

Exploits (3)

exploitdb WRITEUP VERIFIED
by Aung Khant · textwebappsphp
https://www.exploit-db.com/exploits/36685

The exploit describes a URI-redirection vulnerability in CubeCart due to improper input sanitization. It provides example URLs demonstrating how an attacker could redirect users to malicious sites via the 'redir' parameter.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: CubeCart 3.0.20
No auth needed
Prerequisites: Access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Aung Khant · textwebappsphp
https://www.exploit-db.com/exploits/36687

The provided text describes a URI-redirection vulnerability in CubeCart 3.0.20, where unsanitized user input in the 'switch.php' script allows redirection to arbitrary domains. This can be exploited for phishing or other attacks.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: CubeCart 3.0.20
No auth needed
Prerequisites: Access to the vulnerable CubeCart instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Aung Khant · textwebappsphp
https://www.exploit-db.com/exploits/36686

The exploit describes a URI-redirection vulnerability in CubeCart 3.0.20 due to improper input sanitization in the 'goto' parameter. An attacker can craft a malicious URL to redirect users to an arbitrary domain, aiding in phishing attacks.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: CubeCart 3.0.20
No auth needed
Prerequisites: Access to the target application's login page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Exploit mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/02/13/5
Exploit mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/02/18/1
Exploit mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/02/12/4
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/79140
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-02/0058.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/79141
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026711
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51966

Scores

EPSS 0.0296
EPSS Percentile 85.4%

Details

CWE
CWE-20
Status published
Products (21)
cubecart/cubecart 3.0.0
cubecart/cubecart 3.0.1
cubecart/cubecart 3.0.2
cubecart/cubecart 3.0.3
cubecart/cubecart 3.0.4
cubecart/cubecart 3.0.5
cubecart/cubecart 3.0.6
cubecart/cubecart 3.0.7
cubecart/cubecart 3.0.8
cubecart/cubecart 3.0.9
... and 11 more
Published Feb 21, 2012
Tracked Since Feb 18, 2026