SQL injection vulnerability in EC-CUBE Ver2 2.1.2a and earlier, and Ver2 RC 2.3.0-rc1 and earlier, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Software | From | Fixed in |
---|---|---|
ec-cube / ec-cube | 1.5.0-b2 | 1.5.0-b2.x |
ec-cube / ec-cube | - | 2.1.2a.x |
ec-cube / ec-cube | 1.4.7 | 1.4.7.x |
ec-cube / ec-cube | 1.0 | 1.0.x |
ec-cube / ec-cube | - | 2.3.0.x |