Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
lockon ec-cube 2.12.3 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2013-3653
Multiple cross-site scripting (XSS) vulnerabilities in the RecommendSearch feature in the management screen in LOCKON EC-CUBE prior to 2.12.5 allow remote malicious users to inject arbitrary web script or HTML via vectors involving the rank parameter, a different vulnerability th...
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.3
Lockon Ec-cube
NA
CVE-2013-3650
Directory traversal vulnerability in the lfCheckFileName function in data/class/pages/LC_Page_ResizeImage.php in LOCKON EC-CUBE prior to 2.12.5 allows remote malicious users to read arbitrary image files via vectors involving the image parameter to resize_image.php, a different v...
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3
NA
CVE-2013-3654
Directory traversal vulnerability in LOCKON EC-CUBE 2.12.0 up to and including 2.12.4 allows remote malicious users to read arbitrary image files via vectors related to data/class/SC_CheckError.php and data/class/SC_FormParam.php, a different vulnerability than CVE-2013-3650.
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.4
NA
CVE-2013-3651
LOCKON EC-CUBE 2.11.2 up to and including 2.12.4 allows remote malicious users to conduct unspecified PHP code-injection attacks via a crafted string, related to data/class/SC_CheckError.php and data/class/SC_FormParam.php.
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.4
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
1 Github repository
NA
CVE-2013-5995
data/class/helper/SC_Helper_Address.php in the front-features implementation in LOCKON EC-CUBE 2.12.3 up to and including 2.13.0 allows remote authenticated users to obtain sensitive information via unspecified vectors related to addresses.
Lockon Ec-cube 2.12.5
Lockon Ec-cube 2.12.4en
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.6
Lockon Ec-cube 2.13.0
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.6en
Lockon Ec-cube 2.12.5en
Lockon Ec-cube 2.12.3en
NA
CVE-2013-4702
Multiple directory traversal vulnerabilities in the doApiAction function in data/class/api/SC_Api_Operation.php in LOCKON EC-CUBE 2.12.0 up to and including 2.12.5 on Windows allow remote malicious users to read arbitrary files via vectors involving a (1) Operation, (2) Service, ...
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.5
Lockon Ec-cube 2.12.5en
Lockon Ec-cube 2.12.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.4en
Lockon Ec-cube 2.12.3en
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.3enp2
NA
CVE-2013-3652
Cross-site scripting (XSS) vulnerability in data/class/pages/products/LC_Page_Products_List.php in LOCKON EC-CUBE 2.11.0 up to and including 2.12.4 allows remote malicious users to inject arbitrary web script or HTML via vectors involving the classcategory_id2 field, a different ...
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.4
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.12.1
NA
CVE-2013-2315
data/class/pages/forgot/LC_Page_Forgot.php in LOCKON EC-CUBE 2.11.0 up to and including 2.12.3enP2 does not properly validate the input to the password reminder function, which allows remote malicious users to obtain sensitive information via a crafted request.
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.3en
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
NA
CVE-2013-2312
Cross-site scripting (XSS) vulnerability in the shopping-cart screen in LOCKON EC-CUBE 2.11.0 up to and including 2.12.3enP2 allows remote malicious users to inject arbitrary web script or HTML via a crafted URL.
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.3en
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3
NA
CVE-2013-2313
Session fixation vulnerability in LOCKON EC-CUBE 2.11.0 up to and including 2.12.3enP2 allows remote malicious users to hijack web sessions via unspecified vectors.
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.3en
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-35229
privilege escalation
local users
CVE-2024-5405
CVE-2024-27842
CVE-2024-5274
CVE-2024-5378
CVE-2024-34152
hard-coded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »