EC-CUBE CVE-2013-3651 Arbitrary PHP Code Execution Vulnerability

EC-CUBE is prone to an arbitrary PHP code-execution vulnerability.

An attacker can exploit this issue to execute arbitrary PHP code within the context of the web server.

The following versions are vulnerable:

EC-CUBE 2.11.2
EC-CUBE 2.11.3
EC-CUBE 2.11.4
EC-CUBE 2.11.5
EC-CUBE 2.12.0
EC-CUBE 2.12.1
EC-CUBE 2.12.2
EC-CUBE 2.12.3
EC-CUBE 2.12.3en
EC-CUBE 2.12.3enP1
EC-CUBE 2.12.3enP2
EC-CUBE 2.12.4
EC-CUBE 2.12.4en


 

Privacy Statement
Copyright 2010, SecurityFocus