Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
lockon ec-cube 2.11.2 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2013-5991
The displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 up to and including 2.11.5 allows remote malicious users to obtain sensitive information by leveraging incorrect handling of error-log output.
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.1
NA
CVE-2013-5992
Cross-site scripting (XSS) vulnerability in the displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 up to and including 2.11.5 allows remote malicious users to inject arbitrary web script or HTML by leveraging incorrect handling of error-message output.
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.1
NA
CVE-2011-3988
SQL injection vulnerability in data/class/SC_Query.php in EC-CUBE 2.11.0 up to and including 2.11.2 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.1
NA
CVE-2014-0808
Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 up to and including 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is exploited, a user of the affected shopping website may obtain other users' information b...
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.11.1
NA
CVE-2013-3651
LOCKON EC-CUBE 2.11.2 up to and including 2.12.4 allows remote malicious users to conduct unspecified PHP code-injection attacks via a crafted string, related to data/class/SC_CheckError.php and data/class/SC_FormParam.php.
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.12.4
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
1 Github repository
NA
CVE-2013-3652
Cross-site scripting (XSS) vulnerability in data/class/pages/products/LC_Page_Products_List.php in LOCKON EC-CUBE 2.11.0 up to and including 2.12.4 allows remote malicious users to inject arbitrary web script or HTML via vectors involving the classcategory_id2 field, a different ...
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.12.4
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.11.1
NA
CVE-2014-0807
data/class/pages/shopping/LC_Page_Shopping_Deliv.php in LOCKON EC-CUBE 2.4.4 and previous versions, and 2.11.0 up to and including 2.12.2, allows remote malicious users to modify data via unspecified vectors.
Lockon Ec-cube 2.4.0
Lockon Ec-cube 2.4.3
Lockon Ec-cube 2.4.2
Lockon Ec-cube
Lockon Ec-cube 2.4.1
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.11.1
NA
CVE-2013-2312
Cross-site scripting (XSS) vulnerability in the shopping-cart screen in LOCKON EC-CUBE 2.11.0 up to and including 2.12.3enP2 allows remote malicious users to inject arbitrary web script or HTML via a crafted URL.
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.3en
NA
CVE-2013-2313
Session fixation vulnerability in LOCKON EC-CUBE 2.11.0 up to and including 2.12.3enP2 allows remote malicious users to hijack web sessions via unspecified vectors.
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.3en
NA
CVE-2013-2314
Cross-site scripting (XSS) vulnerability in the adminAuthorization function in data/class/helper/SC_Helper_Session.php in LOCKON EC-CUBE 2.11.0 up to and including 2.12.3enP2 allows remote malicious users to inject arbitrary web script or HTML via a crafted URL associated with th...
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.3en
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »