Skip to main content

Vendor/product archive

lockon / ec-cube CVEs

Beta · best-effort

26 CVEs tagged to lockon / ec-cube1 Critical, 4 High, 21 Medium, 0 Low, 0 Unrated.

CVE-2018-0564

Published Apr 20, 2018

Session fixation vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3..4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-CUBE 3.0.7, EC-CUBE 3.0.8, EC…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1201

Published Apr 30, 2016

Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to hijack the authentication of administrators.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1200

Published Apr 30, 2016

The management screen in LOCKON EC-CUBE 3.0.7 through 3.0.9 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerabi…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1199

Published Apr 30, 2016

The login page in the management screen in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to bypass intended IP address restrictions via unspecified vectors, a differe…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5665

Published Oct 27, 2015

Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.3 allows remote attackers to hijack the authentication of arbitrary users for requests that w…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0808

Published Jan 22, 2014

Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is expl…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-0807

Published Jan 22, 2014

data/class/pages/shopping/LC_Page_Shopping_Deliv.php in LOCKON EC-CUBE 2.4.4 and earlier, and 2.11.0 through 2.12.2, allows remote attackers to modify data via unspecified vectors.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5996

Published Nov 21, 2013

Multiple cross-site scripting (XSS) vulnerabilities in shopping/payment.tpl components in LOCKON EC-CUBE 2.11.0 through 2.13.0 allow remote attackers to inject arbitrary web scrip…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5995

Published Nov 21, 2013

data/class/helper/SC_Helper_Address.php in the front-features implementation in LOCKON EC-CUBE 2.12.3 through 2.13.0 allows remote authenticated users to obtain sensitive informat…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5994

Published Nov 21, 2013

data/class/pages/mypage/LC_Page_Mypage_DeliveryAddr.php in LOCKON EC-CUBE 2.11.2 through 2.13.0 allows remote attackers to obtain sensitive information via a direct request, which…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5993

Published Nov 21, 2013

Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.0 allows remote attackers to hijack the authentication of arbitrary users via unspecified vec…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5992

Published Nov 21, 2013

Cross-site scripting (XSS) vulnerability in the displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 through 2.11.5 allows remote attackers to inject arbi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5991

Published Nov 21, 2013

The displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 through 2.11.5 allows remote attackers to obtain sensitive information by leveraging incorrect ha…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4702

Published Aug 30, 2013

Multiple directory traversal vulnerabilities in the doApiAction function in data/class/api/SC_Api_Operation.php in LOCKON EC-CUBE 2.12.0 through 2.12.5 on Windows allow remote att…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3653

Published Jun 30, 2013

Multiple cross-site scripting (XSS) vulnerabilities in the RecommendSearch feature in the management screen in LOCKON EC-CUBE before 2.12.5 allow remote attackers to inject arbitr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3652

Published Jun 30, 2013

Cross-site scripting (XSS) vulnerability in data/class/pages/products/LC_Page_Products_List.php in LOCKON EC-CUBE 2.11.0 through 2.12.4 allows remote attackers to inject arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3654

Published Jun 30, 2013

Directory traversal vulnerability in LOCKON EC-CUBE 2.12.0 through 2.12.4 allows remote attackers to read arbitrary image files via vectors related to data/class/SC_CheckError.php…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3651

Published Jun 30, 2013

LOCKON EC-CUBE 2.11.2 through 2.12.4 allows remote attackers to conduct unspecified PHP code-injection attacks via a crafted string, related to data/class/SC_CheckError.php and da…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3650

Published Jun 30, 2013

Directory traversal vulnerability in the lfCheckFileName function in data/class/pages/LC_Page_ResizeImage.php in LOCKON EC-CUBE before 2.12.5 allows remote attackers to read arbit…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2315

Published May 29, 2013

data/class/pages/forgot/LC_Page_Forgot.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 does not properly validate the input to the password reminder function, which allows remote…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2314

Published May 29, 2013

Cross-site scripting (XSS) vulnerability in the adminAuthorization function in data/class/helper/SC_Helper_Session.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote at…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2313

Published May 29, 2013

Session fixation vulnerability in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to hijack web sessions via unspecified vectors.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2312

Published May 29, 2013

Cross-site scripting (XSS) vulnerability in the shopping-cart screen in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3988

Published Oct 21, 2011

SQL injection vulnerability in data/class/SC_Query.php in EC-CUBE 2.11.0 through 2.11.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1325

Published May 13, 2011

Cross-site request forgery (CSRF) vulnerability in EC-CUBE before 2.11.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2