CVE-2009-4236

The process function in data/class/pages/admin/customer/LC_Page_Admin_Customer_SearchCustomer.php in EC-CUBE Ver2 2.4.0 RC1 through 2.4.1, and Community Edition r18068 through r18428, allows remote attackers to obtain sensitive information (customer data) via unknown vectors related to sessions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ec-cube:ec-cube_ver2:2.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:ec-cube:ec-cube_ver2:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:ec-cube:ec-cube_ver2:r18068:-:community:*:*:*:*:*
cpe:2.3:a:ec-cube:ec-cube_ver2:r18428:-:community:*:*:*:*:*

History

21 Nov 2024, 01:09

Type Values Removed Values Added
References () http://jvn.jp/en/jp/JVN79762947/index.html - () http://jvn.jp/en/jp/JVN79762947/index.html -
References () http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000078.html - () http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000078.html -
References () http://osvdb.org/60685 - () http://osvdb.org/60685 -
References () http://secunia.com/advisories/37603 - Vendor Advisory () http://secunia.com/advisories/37603 - Vendor Advisory
References () http://www.ec-cube.net/info/091127/ - Patch, Vendor Advisory () http://www.ec-cube.net/info/091127/ - Patch, Vendor Advisory
References () http://www.ipa.go.jp/security/vuln/documents/2009/200912_ec-cube.html - () http://www.ipa.go.jp/security/vuln/documents/2009/200912_ec-cube.html -
References () http://www.vupen.com/english/advisories/2009/3421 - Patch, Vendor Advisory () http://www.vupen.com/english/advisories/2009/3421 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/54573 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/54573 -

Information

Published : 2009-12-08 23:30

Updated : 2024-11-21 01:09


NVD link : CVE-2009-4236

Mitre link : CVE-2009-4236

CVE.ORG link : CVE-2009-4236


JSON object : View

Products Affected

ec-cube

  • ec-cube_ver2
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor