| 
[Japanese]
 | 
JVNDB-2008-000063
 | 
EC-CUBE cross-site scripting vulnerability
 | 
 
EC-CUBE provided by LOCKON CO.,LTD. contains a cross-site scripting vulnerability. 
 
EC-CUBE from LOCKON CO.,LTD. is an open source system for creating shopping websites. EC-CUBE contains a cross-site scripting vulnerability. 
This vulnerability is different from JVN#61543834, JVN#26621646, and JVN#99916563. 
 
Naruhisa Tadokoro of Kobe Digital Labo.,Inc. reported this vulnerability to IPA. 
JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.
 
 | 
 
  CVSS V2 Severity: Base Metrics 4.3 (Medium) [IPA Score]
  
    - Access Vector: Network
 
    - Access Complexity: Medium
 
    - Authentication: None
 
    - Confidentiality Impact: None
 
    - Integrity Impact: Partial
 
    - Availability Impact: None
 
   
 
 
  
 
 
 | 
 
	
 
 | 
 
	LOCKON CO.,LTD
	
		- EC-CUBE Ver1 Version 1.4.6 and earlier
 
		- EC-CUBE (community) 1.3.4 and earlier
 
		- EC-CUBE Ver1 Beta Version 1.5.0-beta and earlier
 
		- EC-CUBE (community) Nightly-Build r17319 and earlier
 
		- EC-CUBE Ver2 Version 2.1.2a and earlier
 
		- EC-CUBE Ver2 Beta(RC) Version 2.2.0-beta and earlier
 
		 
 
 | 
 
	
 
 | 
 
An arbitrary script could be executed on the user's web browser.
 
 | 
 
[Update the Software] 
Apply the latest updates provided by the vendor.
 
 | 
 
	LOCKON CO.,LTD
	
 
 | 
 
	- Cross-site Scripting(CWE-79) [IPA Evaluation]
 
 
 
 | 
 
	- CVE-2008-4536 
 
 
 
 | 
 
	- JVN : JVN#36085487 
 
	- National Vulnerability Database (NVD) : CVE-2008-4536 
 
	- IPA SECURITY ALERTS : 200907_ec-cube (Japanese)
 
	- Secunia Advisory : SA32065 
 
	- JVN iPedia (Japanese) : JVNDB-2008-000063 
 
 
 
 | 
 
	- [2008/10/01]
 
  Web page published 
  
 
 |