CVE-2018-0658
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Input validation issue in EC-CUBE Payment Module (2.12) version 3.5.23 and earlier, EC-CUBE Payment Module (2.11) version 2.3.17 and earlier, GMO-PG Payment Module (PG Multi-Payment Service) (2.12) version 3.5.23 and earlier, GMO-PG Payment Module (PG Multi-Payment Service) (2.11) version 2.3.17 and earlier allows an attacker with administrative rights to execute arbitrary PHP code on the server via unspecified vectors.
Problema de validación de entradas en EC-CUBE Payment Module (2.12) en versiones 3.5.23 y anteriores, EC-CUBE Payment Module (2.11) en versiones 2.3.17 y anteriores, GMO-PG Payment Module (PG Multi-Payment Service) (2.12) en versiones 3.5.23 y anteriores y GMO-PG Payment Module (PG Multi-Payment Service) (2.11) en versiones 2.3.17 y anteriores permite que un atacante con permisos de administrador ejecute código PHP arbitrario en el servidor mediante vectores sin especificar.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-27 CVE Reserved
- 2018-09-07 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
http://jvn.jp/en/jp/JVN06372244/index.html | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ec-cube Search vendor "Ec-cube" | Ec-cube Payment Module Search vendor "Ec-cube" for product "Ec-cube Payment Module" | <= 2.3.17 Search vendor "Ec-cube" for product "Ec-cube Payment Module" and version " <= 2.3.17" | - |
Affected
| in | Ec-cube Search vendor "Ec-cube" | Ec-cube Search vendor "Ec-cube" for product "Ec-cube" | 2.11 Search vendor "Ec-cube" for product "Ec-cube" and version "2.11" | - |
Safe
|
Gmo-pg Search vendor "Gmo-pg" | Gmo-pg Payment Module Search vendor "Gmo-pg" for product "Gmo-pg Payment Module" | <= 2.3.17 Search vendor "Gmo-pg" for product "Gmo-pg Payment Module" and version " <= 2.3.17" | - |
Affected
| in | Ec-cube Search vendor "Ec-cube" | Ec-cube Search vendor "Ec-cube" for product "Ec-cube" | 2.11 Search vendor "Ec-cube" for product "Ec-cube" and version "2.11" | - |
Safe
|
Ec-cube Search vendor "Ec-cube" | Ec-cube Payment Module Search vendor "Ec-cube" for product "Ec-cube Payment Module" | <= 3.5.23 Search vendor "Ec-cube" for product "Ec-cube Payment Module" and version " <= 3.5.23" | - |
Affected
| in | Ec-cube Search vendor "Ec-cube" | Ec-cube Search vendor "Ec-cube" for product "Ec-cube" | 2.12 Search vendor "Ec-cube" for product "Ec-cube" and version "2.12" | - |
Safe
|
Gmo-pg Search vendor "Gmo-pg" | Gmo-pg Payment Module Search vendor "Gmo-pg" for product "Gmo-pg Payment Module" | <= 3.5.23 Search vendor "Gmo-pg" for product "Gmo-pg Payment Module" and version " <= 3.5.23" | - |
Affected
| in | Ec-cube Search vendor "Ec-cube" | Ec-cube Search vendor "Ec-cube" for product "Ec-cube" | 2.12 Search vendor "Ec-cube" for product "Ec-cube" and version "2.12" | - |
Safe
|