VYPR
Unrated severityNVD Advisory· Published Oct 3, 2006· Updated Jun 16, 2026

CVE-2006-5107

CVE-2006-5107

Description

Multiple SQL injection vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter in admin/forgot_pass.php, (2) the order_id parameter in view_order.php, (3) the view_doc parameter in view_doc.php, and (4) the order_id parameter in admin/print_order.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Cubecart/Cubecart8 versions
    cpe:2.3:a:devellion:cubecart:2.0.0:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:devellion:cubecart:2.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:devellion:cubecart:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:devellion:cubecart:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:devellion:cubecart:2.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:devellion:cubecart:2.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:devellion:cubecart:2.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:devellion:cubecart:2.0.6:*:*:*:*:*:*:*
    • (no CPE)range: 2.0.x

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.