EC-CUBE Password Reminder Function Information Disclosure Vulnerability
BID:60114
Info
EC-CUBE Password Reminder Function Information Disclosure Vulnerability
| Bugtraq ID: | 60114 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2315 |
| Remote: | Yes |
| Local: | No |
| Published: | May 23 2013 12:00AM |
| Updated: | May 23 2013 12:00AM |
| Credit: | System Friend, lnc |
| Vulnerable: |
EC-CUBE EC-CUBE 2.11.3 EC-CUBE EC-CUBE 2.11.2 EC-CUBE EC-CUBE 2.11.1 EC-CUBE EC-CUBE 2.11 |
| Not Vulnerable: | |
Discussion
EC-CUBE Password Reminder Function Information Disclosure Vulnerability
EC-CUBE is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow attackers to obtain sensitive information that may aid in further attacks.
EC-CUBE 2.11.0 and later are vulnerable.
EC-CUBE is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow attackers to obtain sensitive information that may aid in further attacks.
EC-CUBE 2.11.0 and later are vulnerable.
Exploit / POC
EC-CUBE Password Reminder Function Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
EC-CUBE Password Reminder Function Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
EC-CUBE Password Reminder Function Information Disclosure Vulnerability
References:
References:
- EC-CUBE Homepage (LOCKON CO. LTD.)