← Vulnerability feed

Vulnerability record · CVE-2012-6049 · published 27 November 2012

CVE-2012-6049: Opensolution quick.cart information exposure vulnerability

Opensolution · Quick.Cart

Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, which reveals the installation path in an error message.

5.0 CVSS 2.0 Medium EPSS 1.4% · top 29.5% CWE-200 · Information exposure
5.0CVSS 2.0 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, which reveals the installation path in an error message.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-6049 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2025-67684Opensolution quick.cart path traversal vulnerabilityQuick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart allows a privileged user to u…EPSS 0.83%7.2CVE-2020-35754Opensolution quick.cart code injection vulnerabilityOpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via …EPSS 10%6.9CVE-2026-23797Opensolution quick.cart vulnerabilityIn Quick.Cart user passwords are stored in plaintext form. An attacker with high privileges can display users' password in user editing page. The ven…EPSS 0.26%6.8CVE-2009-4120Opensolution quick.cart cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authentication of the administrator…EPSS 1.00%5.1CVE-2025-67683Opensolution quick.cart cross-site scripting vulnerabilityQuick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when opened, results in arbitrary Jav…EPSS 0.29%4.8CVE-2026-23796Opensolution quick.cart vulnerabilityQuick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This…EPSS 0.28%4.3CVE-2012-6430Opensolution quick.cart cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded before December 19, 2012, allows r…EPSS 3.9%4.3CVE-2008-4140Opensolution quick.cart cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in admin.php in Quick.Cart 3.1 allows remote attackers to inject arbitrary web script or HTML via the query …EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2012-6049), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.