CVE-2013-5996

Lockon Ec-cube - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in shopping/payment.tpl components in LOCKON EC-CUBE 2.11.0 through 2.13.0 allow remote attackers to inject arbitrary web script or HTML via crafted values.

Scores

EPSS 0.0026
EPSS Percentile 48.7%

Details

CWE
CWE-79
Status published
Products (22)
lockon/ec-cube
lockon/ec-cube
lockon/ec-cube
lockon/ec-cube
lockon/ec-cube
lockon/ec-cube
lockon/ec-cube
lockon/ec-cube
lockon/ec-cube
lockon/ec-cube
... and 12 more
Published Nov 21, 2013
Tracked Since Feb 18, 2026