CVE-2009-4236

Metadata

CVE-2009-4236
5.0
jvn.jp, jvndb.jvn.jp, ec-cube.net, ipa.go.jp, vupen.com, exchange.xforce.ibmcloud.com
2009-12-08
2017-08-17 06:10

Description

The process function in data/class/pages/admin/customer/LC_Page_Admin_Customer_SearchCustomer.php in EC-CUBE Ver2 2.4.0 RC1 through 2.4.1, and Community Edition r18068 through r18428, allows remote attackers to obtain sensitive information (customer data) via unknown vectors related to sessions.

Related Vulnerabilities