Vulnerability Database

290,300

Total vulnerabilities in the database

CVE-2009-4060

SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter.

  • Published: Nov 24, 2009
  • Updated: Apr 13, 2023
  • CVE: CVE-2009-4060
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

CWEs:

OWASP TOP 10:

Software From Fixed in
cubecart / cubecart 4.0.1 4.0.1.x
cubecart / cubecart 4.0.0-beta_2 4.0.0-beta_2.x
cubecart / cubecart 3.0.9 3.0.9.x
cubecart / cubecart 3.0.8 3.0.8.x
cubecart / cubecart 3.0.18 3.0.18.x
cubecart / cubecart 3.0.5 3.0.5.x
cubecart / cubecart 4.3.4 4.3.4.x
cubecart / cubecart 4.0.0 4.0.0.x
cubecart / cubecart 3.0.14 3.0.14.x
cubecart / cubecart 3.0.13 3.0.13.x
cubecart / cubecart 4.1.1 4.1.1.x
cubecart / cubecart 4.0.3 4.0.3.x
cubecart / cubecart 3.0.16 3.0.16.x
cubecart / cubecart 3.0.7 3.0.7.x
cubecart / cubecart 3.0.19 3.0.19.x
cubecart / cubecart 4.3.5 4.3.5.x
cubecart / cubecart 4.3.2 4.3.2.x
cubecart / cubecart 3.0.20 3.0.20.x
cubecart / cubecart - 4.3.6.x
cubecart / cubecart 4.3.1 4.3.1.x
cubecart / cubecart 4.2.1 4.2.1.x
cubecart / cubecart 3.0.0 3.0.0.x
cubecart / cubecart 3.0.3 3.0.3.x
cubecart / cubecart 4.1.0 4.1.0.x
cubecart / cubecart 3.0.10 3.0.10.x
cubecart / cubecart 4.1.0-rc_1 4.1.0-rc_1.x
cubecart / cubecart 3.0.11 3.0.11.x
cubecart / cubecart 3.0.2 3.0.2.x
cubecart / cubecart 3.0.12 3.0.12.x
cubecart / cubecart 4.2.2 4.2.2.x
cubecart / cubecart 4.0.0-beta_3 4.0.0-beta_3.x
cubecart / cubecart 4.0.0-rc_1 4.0.0-rc_1.x
cubecart / cubecart 4.2.0 4.2.0.x
cubecart / cubecart 4.0.2 4.0.2.x
cubecart / cubecart 4.1.0-rc_2 4.1.0-rc_2.x
cubecart / cubecart 3.0.17 3.0.17.x
cubecart / cubecart 4.2.3 4.2.3.x
cubecart / cubecart 3.0.15 3.0.15.x
cubecart / cubecart 3.0.6 3.0.6.x
cubecart / cubecart 3.0.4 3.0.4.x
cubecart / cubecart 4.3.0 4.3.0.x
cubecart / cubecart 3.0.1 3.0.1.x
cubecart / cubecart 4.3.3 4.3.3.x