CVE-2006-4527

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/09/2006
Last modified:
05/09/2008

Description

includes/content/gateway.inc.php in CubeCart 3.0.12 and earlier, when magic_quotes_gpc is disabled, uses an insufficiently restrictive regular expression to validate the gateway parameter, which allows remote attackers to conduct PHP remote file inclusion attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:devellion:cubecart:3.0.12:*:*:*:*:*:*:*