← Back

CVE-2014-0808

nvd nist
Published: Jan 22, 2014Modified: Apr 29, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is exploited, a user of the affected shopping website may obtain other users' information by sending a crafted HTTP request.

Affected (11)

Products: Lockon: Ec Cube
1 product
Ec Cube
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Lockon
Version 2.11.0
Version 2.11.0 beta2
Version 2.11.0 beta
Version 2.11.1
Version 2.11.2
Version 2.11.3
Version 2.11.4
Version 2.11.5
Version 2.12.0
Version 2.12.1
Version 2.12.2

References (12)

Source: vultures@jpcert.or.jp
Source: vultures@jpcert.or.jp
Source: vultures@jpcert.or.jp
Vendor Advisory
Source: vultures@jpcert.or.jp
Source: vultures@jpcert.or.jp
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.