Description
Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) r parameter to switch.php or (2) goto parameter to admin/login.php.
Remediation
References
Related Vulnerabilities
Jetty Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-2080)
WordPress Plugin Flight Search Widget and Blocks Cross-Site Scripting (1.1.0)
Python Integer Overflow or Wraparound Vulnerability (CVE-2016-5636)
Oracle Database Server CVE-2020-2737 Vulnerability (CVE-2020-2737)
Jboss EAP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-0248)