Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ec-cube vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-40199
Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote authenticated attacker with an administrative privilege to obtain the product's directory structure information.
Ec-cube Ec-cube 3.0.18
Ec-cube Ec-cube
4.3
CVSSv2
CVE-2021-20751
Cross-site scripting vulnerability in EC-CUBE EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote malicious user to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation.
Ec-cube Ec-cube
Ec-cube Ec-cube 4.0.5.
4.3
CVSSv2
CVE-2013-2312
Cross-site scripting (XSS) vulnerability in the shopping-cart screen in LOCKON EC-CUBE 2.11.0 up to and including 2.12.3enP2 allows remote malicious users to inject arbitrary web script or HTML via a crafted URL.
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.3en
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3
4.3
CVSSv2
CVE-2013-2314
Cross-site scripting (XSS) vulnerability in the adminAuthorization function in data/class/helper/SC_Helper_Session.php in LOCKON EC-CUBE 2.11.0 up to and including 2.12.3enP2 allows remote malicious users to inject arbitrary web script or HTML via a crafted URL associated with th...
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.3en
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.3enp2
4
CVSSv2
CVE-2013-2313
Session fixation vulnerability in LOCKON EC-CUBE 2.11.0 up to and including 2.12.3enP2 allows remote malicious users to hijack web sessions via unspecified vectors.
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.3en
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
5
CVSSv2
CVE-2013-2315
data/class/pages/forgot/LC_Page_Forgot.php in LOCKON EC-CUBE 2.11.0 up to and including 2.12.3enP2 does not properly validate the input to the password reminder function, which allows remote malicious users to obtain sensitive information via a crafted request.
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.3en
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.3enp2
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
4.3
CVSSv2
CVE-2013-3652
Cross-site scripting (XSS) vulnerability in data/class/pages/products/LC_Page_Products_List.php in LOCKON EC-CUBE 2.11.0 up to and including 2.12.4 allows remote malicious users to inject arbitrary web script or HTML via vectors involving the classcategory_id2 field, a different ...
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.4
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.11.2
Lockon Ec-cube 2.11.3
Lockon Ec-cube 2.11.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.5
Lockon Ec-cube 2.12.1
5
CVSSv2
CVE-2013-4702
Multiple directory traversal vulnerabilities in the doApiAction function in data/class/api/SC_Api_Operation.php in LOCKON EC-CUBE 2.12.0 up to and including 2.12.5 on Windows allow remote malicious users to read arbitrary files via vectors involving a (1) Operation, (2) Service, ...
Lockon Ec-cube 2.12.2
Lockon Ec-cube 2.12.3
Lockon Ec-cube 2.12.5
Lockon Ec-cube 2.12.5en
Lockon Ec-cube 2.12.4
Lockon Ec-cube 2.12.0
Lockon Ec-cube 2.12.1
Lockon Ec-cube 2.12.4en
Lockon Ec-cube 2.12.3en
Lockon Ec-cube 2.12.3enp1
Lockon Ec-cube 2.12.3enp2
6.8
CVSSv2
CVE-2016-1201
Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 3.0.0 up to and including 3.0.9 allows remote malicious users to hijack the authentication of administrators.
Lockon Ec-cube 3.0.4
Lockon Ec-cube 3.0.3
Lockon Ec-cube 3.0.2
Lockon Ec-cube 3.0.1
Lockon Ec-cube 3.0.6
Lockon Ec-cube 3.0.5
Lockon Ec-cube 3.0.9
Lockon Ec-cube 3.0.8
Lockon Ec-cube 3.0.7
Lockon Ec-cube 3.0.0
5
CVSSv2
CVE-2016-1199
The login page in the management screen in LOCKON EC-CUBE 3.0.0 up to and including 3.0.9 allows remote malicious users to bypass intended IP address restrictions via unspecified vectors, a different vulnerability than CVE-2016-1200.
Lockon Ec-cube 3.0.0
Lockon Ec-cube 3.0.9
Lockon Ec-cube 3.0.8
Lockon Ec-cube 3.0.7
Lockon Ec-cube 3.0.6
Lockon Ec-cube 3.0.4
Lockon Ec-cube 3.0.2
Lockon Ec-cube 3.0.5
Lockon Ec-cube 3.0.3
Lockon Ec-cube 3.0.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4761
command injection
CVE-2024-3676
IDOR
CVE-2024-30039
CVE-2024-32113
CVE-2024-30049
CVE-2024-4776
SQL injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »