Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Brooky CubeCart漏洞
Vulnerability Description
CubeCart 2.0.4的index.php允许远程攻击者通过无效的语言参数(1)获取Web服务器的完整路径或者(2)执行跨站脚本(XSS)攻击,并在PHP出错信息中输出参数。
CVSS Information
N/A
Vulnerability Type
N/A