THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2014-0808

Assignerjpcert
Reserved2014-01-06
Published2014-01-22
Updated2024-06-11

Description

Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is exploited, a user of the affected shopping website may obtain other users' information by sending a crafted HTTP request.

Problem types

Authorization Bypass Through User-Controlled Key

Product status

2.11.0 through 2.12.2
affected

systems deployed before June 29th
affected

2015
affected

References

http://www.ec-cube.net/info/weakness/weakness.php?id=57

http://jvn.jp/en/jp/JVN51770585/

http://jvndb.jvn.jp/jvndb/JVNDB-2014-000006

https://ec-orange.jp/

https://jvn.jp/en/jp/JVN15637138/

https://jvndb.jvn.jp/jvndb/JVNDB-2024-000054

cve.org CVE-2014-0808

nvd.nist.gov CVE-2014-0808

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2014-0808
© Copyright 2024 THREATINT. Made in Cyprus with +