Unrated severityNVD Advisory· Published Oct 3, 2006· Updated Apr 23, 2026
CVE-2006-5108
CVE-2006-5108
Description
Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the order_id parameter in (1) admin/print_order.php and (2) view_order.php; the (3) site_url and (4) la_search_home parameters and (5) certain language parameters in admin/nav.php; the (6) image parameter in admin/image.php; the (7) site_name, (8) la_adm_header, (9) charset, and (10) certain other parameters in admin/header.inc.php; the (12) la_pow_by parameter in footer.inc.php; and the (13) site_name parameter and (14) certain other parameters in header.inc.php.
Affected products
7cpe:2.3:a:devellion:cubecart:2.0.0:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:devellion:cubecart:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:devellion:cubecart:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:devellion:cubecart:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:devellion:cubecart:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:devellion:cubecart:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:devellion:cubecart:2.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:devellion:cubecart:2.0.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- www.securityfocus.com/bid/20215nvdExploit
- secunia.com/advisories/22175nvdVendor Advisory
- securityreason.com/securityalert/1662nvd
- www.osvdb.org/29246nvd
- www.osvdb.org/29247nvd
- www.osvdb.org/29248nvd
- www.osvdb.org/29249nvd
- www.osvdb.org/29250nvd
- www.osvdb.org/29251nvd
- www.osvdb.org/29252nvd
- www.securityfocus.com/archive/1/447009/100/0/threadednvd
- www.vupen.com/english/advisories/2006/3818nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/29177nvd
News mentions
0No linked articles in our index yet.