CVE-2024-34832

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
06/06/2024
Last modified:
22/08/2024

Description

Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cubecart:cubecart:*:*:*:*:*:*:*:* 6.5.5 (excluding)


References to Advisories, Solutions, and Tools