VendorsLOCKONec-cube3.0.7
Vulnerabilities

LOCKON EC-CUBE 3.0.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2016-1201
Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to hijack the authentication of administrators.
Published 2016-04-30 · Modified
8.8EPSS 0.006
CVE-2016-1200
The management screen in LOCKON EC-CUBE 3.0.7 through 3.0.9 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2016-1199.
Published 2016-04-30 · Modified
6.5EPSS 0.009
CVE-2016-1199
The login page in the management screen in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to bypass intended IP address restrictions via unspecified vectors, a different vulnerability than CVE-2016-1200.
Published 2016-04-30 · Modified
5.3EPSS 0.013