[Japanese]
|
JVNDB-2008-000062
|
EC-CUBE cross-site scripting vulnerability
|
EC-CUBE provided by LOCKON CO.,LTD. contains a cross-site scripting vulnerability.
EC-CUBE from LOCKON CO.,LTD. is an open source system for creating shopping websites. EC-CUBE contains a cross-site scripting vulnerability.
This vulnerability is different from JVN#61543834, JVN#36085487, and JVN#99916563.
Masako Oono of NetAgent Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 4.3 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
LOCKON CO.,LTD
- EC-CUBE Ver1 Version 1.4.6 and earlier
- EC-CUBE (community) 1.3.4 and earlier
- EC-CUBE Ver1 Beta Version 1.5.0-beta and earlier
- EC-CUBE Ver2 Version 2.1.2a and earlier
- EC-CUBE Ver2 Beta(RC) Version 2.1.1-beta and earlier
- EC-CUBE (community) Nightly-Build r17336 and earlier
|
|
An arbitrary script could be executed on the user's web browser.
|
[Update the Software]
Apply the latest updates provided by the vendor.
|
LOCKON CO.,LTD
|
- Cross-site Scripting(CWE-79) [IPA Evaluation]
|
- CVE-2008-4537
|
- JVN : JVN#26621646
- National Vulnerability Database (NVD) : CVE-2008-4537
- IPA SECURITY ALERTS : 200907_ec-cube (Japanese)
- Secunia Advisory : SA32065
- Secunia Advisory : SA32065
- JVN iPedia (Japanese) : JVNDB-2008-000062
|
- [2008/10/01]
Web page published
|