[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256369

 
 

909

 
 

199183

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-0808Date: (C)2014-01-23   (M)2024-06-20


Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is exploited, a user of the affected shopping website may obtain other users' information by sending a crafted HTTP request.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
JVNDB-2014-000006
http://jvn.jp/en/jp/JVN51770585/
http://www.ec-cube.net/info/weakness/weakness.php?id=57
https://ec-orange.jp/
https://jvn.jp/en/jp/JVN15637138/
https://jvndb.jvn.jp/jvndb/JVNDB-2024-000054

© SecPod Technologies