CVE-2013-3651
high
CVSS v3
—
VIR risk
7.5
Description
LOCKON EC-CUBE 2.11.2 through 2.12.4 allows remote attackers to conduct unspecified PHP code-injection attacks via a crafted string, related to data/class/SC_CheckError.php and data/class/SC_FormParam.php.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
References
- http://jvn.jp/en/jp/JVN34900750/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000062
- http://svn.ec-cube.net/open_trac/changeset/22891
- http://www.ec-cube.net/info/weakness/20130626/index.php
- http://www.ec-cube.net/info/weakness/weakness.php?id=49
- http://jvn.jp/en/jp/JVN34900750/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000062
- http://svn.ec-cube.net/open_trac/changeset/22891
- http://www.ec-cube.net/info/weakness/20130626/index.php
- http://www.ec-cube.net/info/weakness/weakness.php?id=49
CWEs
CWE-94
💬 Discuss CVE-2013-3651 on VIR Community →
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.