Devellion
21 CVEs tracked since 2005. Since Feb 2005, none of them reached CISA KEV.
Devellion CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2005-02 | 4 | 0 |
| 2005-03 | 2 | 0 |
| 2005-04 | 1 | 0 |
| 2005-05 | null or fewer | |
| 2005-06 | null or fewer | |
| 2005-07 | null or fewer | |
| 2005-08 | null or fewer | |
| 2005-09 | null or fewer | |
| 2005-10 | 1 | 0 |
| 2005-11 | null or fewer | |
| 2005-12 | null or fewer | |
| 2006-01 | 2 | 0 |
| 2006-02 | 1 | 0 |
| 2006-03 | null or fewer | |
| 2006-04 | null or fewer | |
| 2006-05 | null or fewer | |
| 2006-06 | null or fewer | |
| 2006-07 | null or fewer | |
| 2006-08 | 2 | 0 |
| 2006-09 | 3 | 0 |
| 2006-10 | 3 | 0 |
| 2006-11 | null or fewer | |
| 2006-12 | null or fewer | |
| 2007-01 | null or fewer | |
| 2007-02 | null or fewer | |
| 2007-03 | null or fewer | |
| 2007-04 | null or fewer | |
| 2007-05 | 2 | 0 |
Products
The products that kept showing up in Devellion's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Devellion.
- CVE-2007-2862Multiple SQL injection vulnerabilities in CubeCart 3.0.16 might allow remote attackers to execute arbitrary SQL commands via an unspecified parameter to cart.inc.php and certain other files in an i...7.5
- CVE-2007-2550Multiple CRLF injection vulnerabilities in Devellion CubeCart 3.0.15 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a cook...5.0
- CVE-2006-5109Devellion CubeCart 2.0.x allows remote attackers to obtain sensitive information via a direct request for (1) link_navi.php or (2) spotlight.php, which reveals the path in various error messages. ...5.0
- CVE-2006-5108Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the order_id parameter in (1) admin/print_order.php...6.8
- CVE-2006-5107Multiple SQL injection vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter in admin/forgot_pass.php, (2) the order_i...7.5
- CVE-2006-4527includes/content/gateway.inc.php in CubeCart 3.0.12 and earlier, when magic_quotes_gpc is disabled, uses an insufficiently restrictive regular expression to validate the gateway parameter, which al...2.6
- CVE-2006-4526SQL injection vulnerability in includes/content/viewCat.inc.php in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the s...7.5
- CVE-2006-4525Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the links array.4.3
- CVE-2006-4268Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) file, (2) x, and (3) y parameters in (a)...6.8
- CVE-2006-4267Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) oid parameter in modules/gateway/Protx/confirmed.php and t...7.5
- CVE-2006-0922CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in ...5.0
- CVE-2006-0245Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7)...4.3
- CVE-2006-0064PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter.7.5
- CVE-2005-3152Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir parameter to (1) cart.php or (2) index.php, or (3) ...4.3
- CVE-2005-1033CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend...5.0
The record
- Peak rank
- #25 in Oct 2006
- Busiest month shown
- Feb 2005, 4 CVEs
- Months with a KEV entry
- 0 since Feb 2005
- Monthly snapshots
- 10 since 2005