Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ec-cube vulnerabilities and exploits
(subscribe to this query)
5.5
CVSSv2
CVE-2020-5590
Directory traversal vulnerability in EC-CUBE 3.0.0 to 3.0.18 and 4.0.0 to 4.0.3 allows remote authenticated malicious users to delete arbitrary files and/or directories on the server via unspecified vectors.
Ec-cube Ec-cube
4.3
CVSSv2
CVE-2020-5679
Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintended operations may be conducted.
Ec-cube Ec-cube
5
CVSSv2
CVE-2020-5680
Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote malicious user to cause a denial-of-service (DoS) condition via unspecified vector.
Ec-cube Ec-cube
4
CVSSv2
CVE-2021-20841
Improper access control in Management screen of EC-CUBE 2 series 2.11.2 to 2.17.1 allows a remote authenticated malicious user to bypass access restriction and to alter System settings via unspecified vectors.
Ec-cube Ec-cube
4.3
CVSSv2
CVE-2021-20842
Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote malicious user to hijack the authentication of Administrator and delete Administrator via a specially crafted web page.
Ec-cube Ec-cube
6.5
CVSSv2
CVE-2016-1200
The management screen in LOCKON EC-CUBE 3.0.7 up to and including 3.0.9 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2016-1199.
Lockon Ec-cube 3.0.8
Lockon Ec-cube 3.0.9
Lockon Ec-cube 3.0.7
7.5
CVSSv2
CVE-2011-3988
SQL injection vulnerability in data/class/SC_Query.php in EC-CUBE 2.11.0 up to and including 2.11.2 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Lockon Ec-cube 2.11.0
Lockon Ec-cube 2.11.1
Lockon Ec-cube 2.11.2
4.3
CVSSv2
CVE-2006-6108
Cross-site scripting (XSS) vulnerability in EC-CUBE prior to 1.0.1a-beta allows remote malicious users to inject arbitrary web script or HTML via unknown attack vectors.
Ec-cube Ec-cube 1.0
5
CVSSv2
CVE-2021-20778
Improper access control vulnerability in EC-CUBE 4.0.6 (EC-CUBE 4 series) allows a remote malicious user to bypass access restriction and obtain sensitive information via unspecified vectors.
Ec-cube Ec-cube 4.0.6
4.3
CVSSv2
CVE-2019-6003
Cross-site scripting vulnerability in EC-CUBE plugin 'Amazon Pay Plugin 2.12,2.13' version 2.4.2 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Ec-cube Amazon Pay 2.12
Ec-cube Amazon Pay 2.13
Ec-cube Amazon Pay
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4761
command injection
CVE-2024-3676
IDOR
CVE-2024-30039
CVE-2024-32113
CVE-2024-30049
CVE-2024-4776
SQL injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »