CVE-2005-1033
Last modified
CVE-2005-1033 is a vulnerability of currently unknown severity. CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.. EPSS estimates a 3.03% chance of exploitation in the next 30 days.
Description
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Devellion | Cubecart | 2.0.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-1033?
How severe is CVE-2005-1033?
How do I fix CVE-2005-1033?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-1027Multiple cross-site scripting (XSS) vulnerabilities in PHP-N…
- CVE-2005-1028PHP-Nuke 6.x through 7.6 allows remote attackers to obtain s…
- CVE-2005-1029Multiple SQL injection vulnerabilities in Active Auction Hou…
- CVE-2005-1030Multiple cross-site scripting (XSS) vulnerabilities in Activ…
- CVE-2005-1031RUNCMS 1.1A, and possibly other products based on e-Xoops (e…
- CVE-2005-1032Rejected reason: cart.php in LiteCommerce might allow remote…
- CVE-2005-1034SurgeFTP 2.2m1 allows remote attackers to cause a denial of …
- CVE-2005-1035Multiple buffer overflows in Pavuk before 0.9.32 have unknow…
- CVE-2005-1036FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the…7.8
- CVE-2005-1037Unknown vulnerability in AIX 5.3.0, when configured as an NI…
- CVE-2005-1038crontab in Vixie cron 4.1, when running with the -e option, …
- CVE-2005-1039Race condition in Core Utilities (coreutils) 5.2.1, when (1)…
Are you affected by CVE-2005-1033?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
