VYPR
Critical severity9.8NVD Advisory· Published Feb 8, 2013· Updated Apr 29, 2026

CVE-2013-1465

CVE-2013-1465

Description

The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.

Affected products

1
  • cpe:2.3:a:cubecart:cubecart:*:*:*:*:*:*:*:*
    Range: >=5.0.0,<=5.2.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.