CubeCart 2.0.4 is susceptible to full path disclosure, directory traversal, and cross site scripting bugs.