PT-2013-5903 · Lockon · Ec-Cube

Gen Sato

·

Published

2013-11-21

·

Updated

2013-11-21

·

CVE-2013-5992

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions LOCKON EC-CUBE versions 2.11.0 through 2.11.5
Description A cross-site scripting issue exists due to incorrect handling of error-message output in the displaySystemError function. This allows remote attackers to inject arbitrary web script or HTML.
Recommendations For versions 2.11.0 through 2.11.5, update to a version that fixes the incorrect handling of error-message output in the displaySystemError function to prevent cross-site scripting attacks.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5992

Affected Products

Ec-Cube