Vulnerabilities > Lockon > EC Cube > 3.0.2

DATE CVE VULNERABILITY TITLE RISK
2016-04-30 CVE-2016-1201 Cross-Site Request Forgery (CSRF) vulnerability in Lockon Ec-Cube
Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to hijack the authentication of administrators.
network
lockon CWE-352
6.8
2016-04-30 CVE-2016-1199 Information Exposure vulnerability in Lockon Ec-Cube
The login page in the management screen in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to bypass intended IP address restrictions via unspecified vectors, a different vulnerability than CVE-2016-1200.
network
low complexity
lockon CWE-200
5.0