Known Vulnerabilities for products from Lockon
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Lockon".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2018-0564 json | Session fixation vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3..4, EC-CUBE ... | 8.1 - HIGH | 2018-04-20 | 2018-05-24 |
| CVE-2016-1201 json | Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to hijack the a... | Not Provided | 2016-04-30 | 2026-05-06 |
| CVE-2016-1200 json | The management screen in LOCKON EC-CUBE 3.0.7 through 3.0.9 allows remote authenticated users to bypass intended access restr... | Not Provided | 2016-04-30 | 2026-05-06 |
| CVE-2016-1199 json | The login page in the management screen in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to bypass intended IP a... | Not Provided | 2016-04-30 | 2026-05-06 |
| CVE-2015-5665 json | Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.3 allows remote attackers to hijack the... | Not Provided | 2015-10-27 | 2026-05-06 |
| CVE-2014-0808 json | Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems deployed... | Not Provided | 2014-01-22 | 2026-04-29 |
| CVE-2014-0807 json | data/class/pages/shopping/LC_Page_Shopping_Deliv.php in LOCKON EC-CUBE 2.4.4 and earlier, and 2.11.0 through 2.12.2, allows r... | Not Provided | 2014-01-22 | 2026-04-29 |
| CVE-2013-5996 json | Multiple cross-site scripting (XSS) vulnerabilities in shopping/payment.tpl components in LOCKON EC-CUBE 2.11.0 through 2.13.... | Not Provided | 2013-11-21 | 2026-04-29 |
| CVE-2013-5995 json | data/class/helper/SC_Helper_Address.php in the front-features implementation in LOCKON EC-CUBE 2.12.3 through 2.13.0 allows r... | Not Provided | 2013-11-21 | 2026-04-29 |
| CVE-2013-5994 json | data/class/pages/mypage/LC_Page_Mypage_DeliveryAddr.php in LOCKON EC-CUBE 2.11.2 through 2.13.0 allows remote attackers to ob... | Not Provided | 2013-11-21 | 2026-04-29 |
| CVE-2013-5993 json | Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.0 allows remote attackers to hijack the... | Not Provided | 2013-11-21 | 2026-04-29 |
| CVE-2013-5992 json | Cross-site scripting (XSS) vulnerability in the displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0... | Not Provided | 2013-11-21 | 2026-04-29 |
| CVE-2013-5991 json | The displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 through 2.11.5 allows remote attackers to o... | Not Provided | 2013-11-21 | 2026-04-29 |
| CVE-2013-4702 json | Multiple directory traversal vulnerabilities in the doApiAction function in data/class/api/SC_Api_Operation.php in LOCKON EC-... | Not Provided | 2013-08-30 | 2026-04-29 |
| CVE-2013-3654 json | Directory traversal vulnerability in LOCKON EC-CUBE 2.12.0 through 2.12.4 allows remote attackers to read arbitrary image fil... | Not Provided | 2013-06-30 | 2026-04-29 |
| CVE-2013-3653 json | Multiple cross-site scripting (XSS) vulnerabilities in the RecommendSearch feature in the management screen in LOCKON EC-CUBE... | Not Provided | 2013-06-30 | 2026-04-29 |
| CVE-2013-3652 json | Cross-site scripting (XSS) vulnerability in data/class/pages/products/LC_Page_Products_List.php in LOCKON EC-CUBE 2.11.0 thro... | Not Provided | 2013-06-30 | 2026-04-29 |
| CVE-2013-3651 json | LOCKON EC-CUBE 2.11.2 through 2.12.4 allows remote attackers to conduct unspecified PHP code-injection attacks via a crafted ... | Not Provided | 2013-06-30 | 2026-04-29 |
| CVE-2013-3650 json | Directory traversal vulnerability in the lfCheckFileName function in data/class/pages/LC_Page_ResizeImage.php in LOCKON EC-CU... | Not Provided | 2013-06-30 | 2026-04-29 |
| CVE-2013-2315 json | data/class/pages/forgot/LC_Page_Forgot.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 does not properly validate the input t... | Not Provided | 2013-05-29 | 2026-04-29 |
Known software with vulnerabilities from Lockon
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Lockon | Ec-cube | 1.1.0 |