Refine your search

4 vulnerabilities found for by Frogman Office Inc.

CVE-2017-10886 (GCVE-0-2017-10886)
Vulnerability from cvelistv5
Published
2017-11-17 14:00
Modified
2024-08-05 17:50
Severity ?
CWE
  • Cross-site scripting
Summary
Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
References
https://jvn.jp/en/jp/JVN29602086/index.html third-party-advisory, x_refsource_JVN
http://tips.cs-cart.jp/fix-jvn-29602086.html x_refsource_CONFIRM
Impacted products
Vendor Product Version
Frogman Office Inc. CS-Cart Japanese Edition Version: v4.3.10 and earlier (excluding v2 and v3)
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-05T17:50:12.728Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "name": "JVN#29602086",
            "tags": [
              "third-party-advisory",
              "x_refsource_JVN",
              "x_transferred"
            ],
            "url": "https://jvn.jp/en/jp/JVN29602086/index.html"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "http://tips.cs-cart.jp/fix-jvn-29602086.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "CS-Cart Japanese Edition",
          "vendor": "Frogman Office Inc.",
          "versions": [
            {
              "status": "affected",
              "version": "v4.3.10 and earlier (excluding v2 and v3)"
            }
          ]
        },
        {
          "product": "CS-Cart Multivendor Japanese Edition",
          "vendor": "Frogman Office Inc.",
          "versions": [
            {
              "status": "affected",
              "version": "v4.3.10 and earlier (excluding v2 and v3)"
            }
          ]
        }
      ],
      "datePublic": "2017-11-13T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Cross-site scripting",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2017-11-17T13:57:01.000Z",
        "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "shortName": "jpcert"
      },
      "references": [
        {
          "name": "JVN#29602086",
          "tags": [
            "third-party-advisory",
            "x_refsource_JVN"
          ],
          "url": "https://jvn.jp/en/jp/JVN29602086/index.html"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "http://tips.cs-cart.jp/fix-jvn-29602086.html"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "vultures@jpcert.or.jp",
          "ID": "CVE-2017-10886",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "CS-Cart Japanese Edition",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "v4.3.10 and earlier (excluding v2 and v3)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "CS-Cart Multivendor Japanese Edition",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "v4.3.10 and earlier (excluding v2 and v3)"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Frogman Office Inc."
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "Cross-site scripting"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "JVN#29602086",
              "refsource": "JVN",
              "url": "https://jvn.jp/en/jp/JVN29602086/index.html"
            },
            {
              "name": "http://tips.cs-cart.jp/fix-jvn-29602086.html",
              "refsource": "CONFIRM",
              "url": "http://tips.cs-cart.jp/fix-jvn-29602086.html"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
    "assignerShortName": "jpcert",
    "cveId": "CVE-2017-10886",
    "datePublished": "2017-11-17T14:00:00.000Z",
    "dateReserved": "2017-07-04T00:00:00.000Z",
    "dateUpdated": "2024-08-05T17:50:12.728Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2017-2138 (GCVE-0-2017-2138)
Vulnerability from cvelistv5
Published
2017-08-02 16:00
Modified
2024-08-05 13:39
Severity ?
CWE
  • Cross-site request forgery
Summary
Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors.
References
Impacted products
Vendor Product Version
Frogman Office Inc. CS-Cart Japanese Edition Version: v4.3.10 and earlier (excluding v2 and v3)
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-05T13:39:32.358Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "name": "JVN#87770873",
            "tags": [
              "third-party-advisory",
              "x_refsource_JVN",
              "x_transferred"
            ],
            "url": "https://jvn.jp/en/jp/JVN87770873/index.html"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "http://tips.cs-cart.jp/fix-csrf-20170406.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "CS-Cart Japanese Edition",
          "vendor": "Frogman Office Inc.",
          "versions": [
            {
              "status": "affected",
              "version": "v4.3.10 and earlier (excluding v2 and v3)"
            }
          ]
        },
        {
          "product": "CS-Cart Multivendor Japanese Edition",
          "vendor": "Frogman Office Inc.",
          "versions": [
            {
              "status": "affected",
              "version": "v4.3.10 and earlier (excluding v2 and v3)"
            }
          ]
        }
      ],
      "datePublic": "2017-08-02T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Cross-site request forgery",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2017-08-02T15:57:02.000Z",
        "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "shortName": "jpcert"
      },
      "references": [
        {
          "name": "JVN#87770873",
          "tags": [
            "third-party-advisory",
            "x_refsource_JVN"
          ],
          "url": "https://jvn.jp/en/jp/JVN87770873/index.html"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "http://tips.cs-cart.jp/fix-csrf-20170406.html"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "vultures@jpcert.or.jp",
          "ID": "CVE-2017-2138",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "CS-Cart Japanese Edition",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "v4.3.10 and earlier (excluding v2 and v3)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "CS-Cart Multivendor Japanese Edition",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "v4.3.10 and earlier (excluding v2 and v3)"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Frogman Office Inc."
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "Cross-site request forgery"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "JVN#87770873",
              "refsource": "JVN",
              "url": "https://jvn.jp/en/jp/JVN87770873/index.html"
            },
            {
              "name": "http://tips.cs-cart.jp/fix-csrf-20170406.html",
              "refsource": "MISC",
              "url": "http://tips.cs-cart.jp/fix-csrf-20170406.html"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
    "assignerShortName": "jpcert",
    "cveId": "CVE-2017-2138",
    "datePublished": "2017-08-02T16:00:00.000Z",
    "dateReserved": "2016-12-01T00:00:00.000Z",
    "dateUpdated": "2024-08-05T13:39:32.358Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2017-2143 (GCVE-0-2017-2143)
Vulnerability from cvelistv5
Published
2017-04-28 16:00
Modified
2024-08-05 13:48
Severity ?
CWE
  • Fails to restrict access
Summary
CS-Cart Japanese Edition v4.3.10-jp-1 and earlier, CS-Cart Multivendor Japanese Edition v4.3.10-jp-1 and earlier allows remote attackers to bypass access restriction to create a request to return a customer purchased item via rma.post.php.
References
http://tips.cs-cart.jp/fix-jvn-25598952.html x_refsource_MISC
http://jvn.jp/en/jp/JVN25598952/index.html third-party-advisory, x_refsource_JVN
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-05T13:48:03.502Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "http://tips.cs-cart.jp/fix-jvn-25598952.html"
          },
          {
            "name": "JVN#25598952",
            "tags": [
              "third-party-advisory",
              "x_refsource_JVN",
              "x_transferred"
            ],
            "url": "http://jvn.jp/en/jp/JVN25598952/index.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "CS-Cart Japanese Edition",
          "vendor": "Frogman Office Inc.",
          "versions": [
            {
              "status": "affected",
              "version": "v4.3.10-jp-1 and earlier"
            }
          ]
        },
        {
          "product": "CS-Cart Multivendor Japanese Edition",
          "vendor": "Frogman Office Inc.",
          "versions": [
            {
              "status": "affected",
              "version": "v4.3.10-jp-1 and earlier"
            }
          ]
        }
      ],
      "datePublic": "2017-04-28T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "CS-Cart Japanese Edition v4.3.10-jp-1 and earlier, CS-Cart Multivendor Japanese Edition v4.3.10-jp-1 and earlier allows remote attackers to bypass access restriction to create a request to return a customer purchased item via rma.post.php."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Fails to restrict access",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2017-04-28T15:57:01.000Z",
        "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "shortName": "jpcert"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "http://tips.cs-cart.jp/fix-jvn-25598952.html"
        },
        {
          "name": "JVN#25598952",
          "tags": [
            "third-party-advisory",
            "x_refsource_JVN"
          ],
          "url": "http://jvn.jp/en/jp/JVN25598952/index.html"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "vultures@jpcert.or.jp",
          "ID": "CVE-2017-2143",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "CS-Cart Japanese Edition",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "v4.3.10-jp-1 and earlier"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "CS-Cart Multivendor Japanese Edition",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "v4.3.10-jp-1 and earlier"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Frogman Office Inc."
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "CS-Cart Japanese Edition v4.3.10-jp-1 and earlier, CS-Cart Multivendor Japanese Edition v4.3.10-jp-1 and earlier allows remote attackers to bypass access restriction to create a request to return a customer purchased item via rma.post.php."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "Fails to restrict access"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "http://tips.cs-cart.jp/fix-jvn-25598952.html",
              "refsource": "MISC",
              "url": "http://tips.cs-cart.jp/fix-jvn-25598952.html"
            },
            {
              "name": "JVN#25598952",
              "refsource": "JVN",
              "url": "http://jvn.jp/en/jp/JVN25598952/index.html"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
    "assignerShortName": "jpcert",
    "cveId": "CVE-2017-2143",
    "datePublished": "2017-04-28T16:00:00.000Z",
    "dateReserved": "2016-12-01T00:00:00.000Z",
    "dateUpdated": "2024-08-05T13:48:03.502Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

CVE-2017-2139 (GCVE-0-2017-2139)
Vulnerability from cvelistv5
Published
2017-04-28 16:00
Modified
2024-08-05 13:39
Severity ?
CWE
  • Fails to restrict access
Summary
CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer information via orders.pre.php.
References
http://jvn.jp/en/jp/JVN14396697/index.html third-party-advisory, x_refsource_JVN
http://tips.cs-cart.jp/fix-jvn-14396697.html x_refsource_MISC
Impacted products
Vendor Product Version
Frogman Office Inc. CS-Cart Japanese Edition Version: v4.3.10 and earlier (excluding v2 and v3)
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-05T13:39:32.360Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "name": "JVN#14396697",
            "tags": [
              "third-party-advisory",
              "x_refsource_JVN",
              "x_transferred"
            ],
            "url": "http://jvn.jp/en/jp/JVN14396697/index.html"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "http://tips.cs-cart.jp/fix-jvn-14396697.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "CS-Cart Japanese Edition",
          "vendor": "Frogman Office Inc.",
          "versions": [
            {
              "status": "affected",
              "version": "v4.3.10 and earlier (excluding v2 and v3)"
            }
          ]
        },
        {
          "product": "CS-Cart Multivendor Japanese Edition",
          "vendor": "Frogman Office Inc.",
          "versions": [
            {
              "status": "affected",
              "version": "v4.3.10 and earlier (excluding v2 and v3)"
            }
          ]
        }
      ],
      "datePublic": "2017-04-28T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer information via orders.pre.php."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Fails to restrict access",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2017-04-28T15:57:01.000Z",
        "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "shortName": "jpcert"
      },
      "references": [
        {
          "name": "JVN#14396697",
          "tags": [
            "third-party-advisory",
            "x_refsource_JVN"
          ],
          "url": "http://jvn.jp/en/jp/JVN14396697/index.html"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "http://tips.cs-cart.jp/fix-jvn-14396697.html"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "vultures@jpcert.or.jp",
          "ID": "CVE-2017-2139",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "CS-Cart Japanese Edition",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "v4.3.10 and earlier (excluding v2 and v3)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "CS-Cart Multivendor Japanese Edition",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "v4.3.10 and earlier (excluding v2 and v3)"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Frogman Office Inc."
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer information via orders.pre.php."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "Fails to restrict access"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "JVN#14396697",
              "refsource": "JVN",
              "url": "http://jvn.jp/en/jp/JVN14396697/index.html"
            },
            {
              "name": "http://tips.cs-cart.jp/fix-jvn-14396697.html",
              "refsource": "MISC",
              "url": "http://tips.cs-cart.jp/fix-jvn-14396697.html"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
    "assignerShortName": "jpcert",
    "cveId": "CVE-2017-2139",
    "datePublished": "2017-04-28T16:00:00.000Z",
    "dateReserved": "2016-12-01T00:00:00.000Z",
    "dateUpdated": "2024-08-05T13:39:32.360Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}