CVE Database
/

CVE-2013-4702

Back to search

CVE-2013-4702

Published: Aug 30, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple directory traversal vulnerabilities in the doApiAction function in data/class/api/SC_Api_Operation.php in LOCKON EC-CUBE 2.12.0 through 2.12.5 on Windows allow remote attackers to read arbitrary files via vectors involving a (1) Operation, (2) Service, (3) Style, (4) Validate, or (5) Version value.

VendorProductVersions

n/a

n/a

affected
n/a

References

96756
vdb-entry
x_refsource_OSVDB
JVN#15973066
third-party-advisory
x_refsource_JVN
JVNDB-2013-000081
third-party-advisory
x_refsource_JVNDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now