Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) r parameter to switch.php or (2) goto parameter to admin/login.php.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2012-02-21 13:31
Updated : 2025-04-11 00:51
NVD link : CVE-2012-0865
Mitre link : CVE-2012-0865
CVE.ORG link : CVE-2012-0865
JSON object : View
Products Affected
                cubecart
- cubecart
 
CWE
                
                    
                        
                        CWE-20
                        
            Improper Input Validation
