CVE-2009-4236

The process function in data/class/pages/admin/customer/LC_Page_Admin_Customer_SearchCustomer.php in EC-CUBE Ver2 2.4.0 RC1 through 2.4.1, and Community Edition r18068 through r18428, allows remote attackers to obtain sensitive information (customer data) via unknown vectors related to sessions.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ec-cube:ec-cube_ver2:r18068:-:community:*:*:*:*:*
cpe:2.3:a:ec-cube:ec-cube_ver2:r18428:-:community:*:*:*:*:*
cpe:2.3:a:ec-cube:ec-cube_ver2:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:ec-cube:ec-cube_ver2:2.4.0:rc1:*:*:*:*:*:*

Information

Published : 2009-12-08 15:30

Updated : 2017-08-16 18:31


NVD link : CVE-2009-4236

Mitre link : CVE-2009-4236


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

ec-cube

  • ec-cube_ver2