Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ec-cube vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2013-5995
data/class/helper/SC_Helper_Address.php in the front-features implementation in LOCKON EC-CUBE 2.12.3 up to and including 2.13.0 allows remote authenticated users to obtain sensitive information via unspecified vectors related to addresses.
Lockon Ec-cube 2.12.5
Lockon Ec-cube 2.12.4en
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.6
Lockon Ec-cube 2.13.0
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.6en
Lockon Ec-cube 2.12.5en
Lockon Ec-cube 2.12.3en
NA
CVE-2014-0808
The lfCheckError function in data/class/pages/shopping/LC_Page_Shopping_Multiple.php in LOCKON EC-CUBE 2.11.0 up to and including 2.12.2 allows remote malicious users to obtain sensitive shipping information via unspecified vectors.
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
NA
CVE-2013-3651
LOCKON EC-CUBE 2.11.2 up to and including 2.12.4 allows remote malicious users to conduct unspecified PHP code-injection attacks via a crafted string, related to data/class/SC_CheckError.php and data/class/SC_FormParam.php.
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.4
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
1 Github repository
NA
CVE-2013-5991
The displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 up to and including 2.11.5 allows remote malicious users to obtain sensitive information by leveraging incorrect handling of error-log output.
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.4
NA
CVE-2013-5992
Cross-site scripting (XSS) vulnerability in the displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 up to and including 2.11.5 allows remote malicious users to inject arbitrary web script or HTML by leveraging incorrect handling of error-message output.
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.5
NA
CVE-2013-3650
Directory traversal vulnerability in the lfCheckFileName function in data/class/pages/LC_Page_ResizeImage.php in LOCKON EC-CUBE prior to 2.12.5 allows remote malicious users to read arbitrary image files via vectors involving the image parameter to resize_image.php, a different v...
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3
NA
CVE-2013-3653
Multiple cross-site scripting (XSS) vulnerabilities in the RecommendSearch feature in the management screen in LOCKON EC-CUBE prior to 2.12.5 allow remote malicious users to inject arbitrary web script or HTML via vectors involving the rank parameter, a different vulnerability th...
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.3
Lockon Ec-cube
NA
CVE-2013-3654
Directory traversal vulnerability in LOCKON EC-CUBE 2.12.0 up to and including 2.12.4 allows remote malicious users to read arbitrary image files via vectors related to data/class/SC_CheckError.php and data/class/SC_FormParam.php, a different vulnerability than CVE-2013-3650.
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.4
5.4
CVSSv3
CVE-2022-38975
DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote malicious user to inject an arbitrary script by having an administrative user of the product to visit a specially crafted page.
Ec-cube Ec-cube
6.5
CVSSv3
CVE-2021-20842
Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote malicious user to hijack the authentication of Administrator and delete Administrator via a specially crafted web page.
Ec-cube Ec-cube
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33228
CVE-2024-20361
log injection
bypass
CVE-2024-4985
CVE-2024-35223
CVE-2024-29849
CVE-2024-31893
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »