EC-CUBE Two Unspecified SQL Injection Vulnerabilities
Description
Two vulnerabilities have been reported in EC-CUBE, which can be exploited by malicious people to conduct SQL injection attacks.
Certain unspecified input is not properly sanitised in data/class/SC_Query.php before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
The vulnerabilities are reported in versions 2.11.0 through 2.11.2.