CVE Vulnerabilities

CVE-2013-2313

Improper Authentication

Published: May 29, 2013 | Modified: Jun 04, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Session fixation vulnerability in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to hijack web sessions via unspecified vectors.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Ec-cube Lockon 2.11.2 2.11.2
Ec-cube Lockon 2.11.0 2.11.0
Ec-cube Lockon 2.11.3 2.11.3
Ec-cube Lockon 2.11.5 2.11.5
Ec-cube Lockon 2.11.4 2.11.4
Ec-cube Lockon 2.11.1 2.11.1

Potential Mitigations

References