Vulnerability Name: | CVE-2009-3904 (CCN-54062) | ||||||||||||||||
Assigned: | 2009-10-30 | ||||||||||||||||
Published: | 2009-10-30 | ||||||||||||||||
Updated: | 2018-10-10 | ||||||||||||||||
Summary: | classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to bypass restrictions and gain administrative access via a HTTP request that contains an empty (1) sessID (ccAdmin cookie), (2) X_CLUSTER_CLIENT_IP header, or (3) User-Agent header. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri Oct 30 2009 CubeCart 4 Session Management Bypass Source: MITRE Type: CNA CVE-2009-3904 Source: CONFIRM Type: UNKNOWN http://forums.cubecart.com/index.php?showtopic=39691?read=1 Source: CONFIRM Type: Patch http://forums.cubecart.com/index.php?showtopic=39748 Source: CCN Type: SA37197 CubeCart Administrative Session Handling Security Bypass Vulnerability Source: SECUNIA Type: Vendor Advisory 37197 Source: CCN Type: SECTRACK ID: 1023120 CubeCart Session Management Flaw Lets Remote Users Gain Administrative Access Source: CCN Type: acunetix Web Site CubeCart 4 session management bypass leads to administrator access Source: MISC Type: Exploit http://www.acunetix.com/blog/websecuritynews/cubecart-4-session-management-bypass-leads-to-administrator-access/ Source: CCN Type: CubeCart Web site CubeCart eCommerce - Free online shopping cart software Source: DEBIAN Type: DSA-1941 poppler -- several vulnerabilities Source: CCN Type: OSVDB ID: 59696 CubeCart classes/session/cc_admin_session.php Multiple HTTP Header ccAdmin Cookie Manipulation Admin Authentication Bypass Source: BUGTRAQ Type: UNKNOWN 20091030 CubeCart 4 Session Management Bypass Source: BID Type: Exploit 36882 Source: CCN Type: BID-36882 CubeCart 'admin.php' Authentication Bypass Vulnerability Source: SECTRACK Type: Exploit 1023120 Source: VUPEN Type: Patch, Vendor Advisory ADV-2009-3113 Source: XF Type: UNKNOWN cubecart-session-security-bypass(54062) Source: XF Type: UNKNOWN cubecart-session-security-bypass(54062) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |