Vulnerabilities > EC Cube > EC Cube > 1.5.0

DATE CVE VULNERABILITY TITLE RISK
2008-11-06 CVE-2008-4991 SQL Injection vulnerability in Ec-Cube
SQL injection vulnerability in LOCKON CO.,LTD.
network
low complexity
ec-cube CWE-89
7.5
2008-10-10 CVE-2008-4537 Cross-Site Scripting vulnerability in Ec-Cube
Cross-site scripting (XSS) vulnerability in EC-CUBE Ver1 1.4.6 and earlier, Ver1 Beta 1.5.0-beta and earlier, Ver2 2.1.2a and earlier, Ver2 Beta(RC) 2.1.1-beta and earlier, Community Edition 1.3.4 and earlier, and Community Edition Nightly-Build r17336 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-4535 and CVE-2008-4536.
network
ec-cube CWE-79
4.3
2008-10-10 CVE-2008-4536 Cross-Site Scripting vulnerability in Ec-Cube
Cross-site scripting (XSS) vulnerability in EC-CUBE Ver1 1.4.6 and earlier, Ver1 Beta 1.5.0-beta and earlier, Ver2 2.1.2a and earlier, Ver2 Beta(RC) 2.2.0-beta and earlier, Community Edition 1.3.4 and earlier, and Community Edition Nightly-Build r17319 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-4535 and CVE-2008-4537.
network
ec-cube CWE-79
4.3
2008-10-10 CVE-2008-4535 Cross-Site Scripting vulnerability in Ec-Cube
Cross-site scripting (XSS) vulnerability in EC-CUBE Ver2 2.1.2a and earlier, EC-CUBE Ver2 Beta(RC) 2.2.0-beta and earlier, and EC-CUBE Community Edition Nighly-Build r17623 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-4536 and CVE-2008-4537.
network
ec-cube CWE-79
4.3
2008-10-10 CVE-2008-4534 SQL Injection vulnerability in Ec-Cube
SQL injection vulnerability in EC-CUBE Ver2 2.1.2a and earlier, and Ver2 RC 2.3.0-rc1 and earlier, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
ec-cube CWE-89
7.5