Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2013-3651

LOCKON EC-CUBE 2.11.2 through 2.12.4 allows remote attackers to conduct unspecified PHP code-injection attacks via a crafted string, related to data/class/SC_CheckError.php and data/class/SC_FormParam.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.101
EPSS Ranking 92.7%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2013-3651
  • Lockon » Ec-Cube » Version: 2.11.2
    cpe:2.3:a:lockon:ec-cube:2.11.2
  • Lockon » Ec-Cube » Version: 2.11.3
    cpe:2.3:a:lockon:ec-cube:2.11.3
  • Lockon » Ec-Cube » Version: 2.11.4
    cpe:2.3:a:lockon:ec-cube:2.11.4
  • Lockon » Ec-Cube » Version: 2.11.5
    cpe:2.3:a:lockon:ec-cube:2.11.5
  • Lockon » Ec-Cube » Version: 2.12.0
    cpe:2.3:a:lockon:ec-cube:2.12.0
  • Lockon » Ec-Cube » Version: 2.12.1
    cpe:2.3:a:lockon:ec-cube:2.12.1
  • Lockon » Ec-Cube » Version: 2.12.2
    cpe:2.3:a:lockon:ec-cube:2.12.2
  • Lockon » Ec-Cube » Version: 2.12.3
    cpe:2.3:a:lockon:ec-cube:2.12.3
  • Lockon » Ec-Cube » Version: 2.12.4
    cpe:2.3:a:lockon:ec-cube:2.12.4


Contact Us

Shodan ® - All rights reserved