Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
lockon ec-cube 2.12.1 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2013-3653
Multiple cross-site scripting (XSS) vulnerabilities in the RecommendSearch feature in the management screen in LOCKON EC-CUBE prior to 2.12.5 allow remote malicious users to inject arbitrary web script or HTML via vectors involving the rank parameter, a different vulnerability th...
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube
NA
CVE-2013-3650
Directory traversal vulnerability in the lfCheckFileName function in data/class/pages/LC_Page_ResizeImage.php in LOCKON EC-CUBE prior to 2.12.5 allows remote malicious users to read arbitrary image files via vectors involving the image parameter to resize_image.php, a different v...
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube
NA
CVE-2013-3654
Directory traversal vulnerability in LOCKON EC-CUBE 2.12.0 up to and including 2.12.4 allows remote malicious users to read arbitrary image files via vectors related to data/class/SC_CheckError.php and data/class/SC_FormParam.php, a different vulnerability than CVE-2013-3650.
Lockon Ec-cube 2.12.4
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
NA
CVE-2014-0808
Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 up to and including 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is exploited, a user of the affected shopping website may obtain other users' information b...
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.11.1
NA
CVE-2013-3651
LOCKON EC-CUBE 2.11.2 up to and including 2.12.4 allows remote malicious users to conduct unspecified PHP code-injection attacks via a crafted string, related to data/class/SC_CheckError.php and data/class/SC_FormParam.php.
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.12.4
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
1 Github repository
NA
CVE-2013-3652
Cross-site scripting (XSS) vulnerability in data/class/pages/products/LC_Page_Products_List.php in LOCKON EC-CUBE 2.11.0 up to and including 2.12.4 allows remote malicious users to inject arbitrary web script or HTML via vectors involving the classcategory_id2 field, a different ...
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.12.4
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.11.1
NA
CVE-2013-4702
Multiple directory traversal vulnerabilities in the doApiAction function in data/class/api/SC_Api_Operation.php in LOCKON EC-CUBE 2.12.0 up to and including 2.12.5 on Windows allow remote malicious users to read arbitrary files via vectors involving a (1) Operation, (2) Service, ...
Lockon Ec-cube 2.12.5en
Lockon Ec-cube 2.12.5
Lockon Ec-cube 2.12.4
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.4en
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.3en
NA
CVE-2014-0807
data/class/pages/shopping/LC_Page_Shopping_Deliv.php in LOCKON EC-CUBE 2.4.4 and previous versions, and 2.11.0 up to and including 2.12.2, allows remote malicious users to modify data via unspecified vectors.
Lockon Ec-cube 2.4.0
Lockon Ec-cube 2.4.3
Lockon Ec-cube 2.4.2
Lockon Ec-cube
Lockon Ec-cube 2.4.1
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.11.1
NA
CVE-2013-2312
Cross-site scripting (XSS) vulnerability in the shopping-cart screen in LOCKON EC-CUBE 2.11.0 up to and including 2.12.3enP2 allows remote malicious users to inject arbitrary web script or HTML via a crafted URL.
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.3en
NA
CVE-2013-2313
Session fixation vulnerability in LOCKON EC-CUBE 2.11.0 up to and including 2.12.3enP2 allows remote malicious users to hijack web sessions via unspecified vectors.
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.3en
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »