Medium severity4.3NVD Advisory· Published Dec 30, 2015· Updated May 6, 2026
CVE-2015-7784
CVE-2015-7784
Description
SQL injection vulnerability in the BOKUBLOCK (1) BbAdminViewsControl213 plugin before 1.1 and (2) BbAdminViewsControl plugin before 2.1 for EC-CUBE allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected products
2- cpe:2.3:a:bokublock:bbadminviewscontrol:*:*:*:*:*:ec-cube:*:*Range: <=2.0
- cpe:2.3:a:bokublock:bbadminviewscontrol213:*:*:*:*:*:ec-cube:*:*Range: <=1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- jvn.jp/en/jp/JVN55545372/index.htmlnvdVendor Advisory
- jvndb.jvn.jp/jvndb/JVNDB-2015-000190nvdVendor Advisory
- www.ec-cube.net/products/detail.phpnvdVendor Advisory
- www.ec-cube.net/products/detail.phpnvdVendor Advisory
News mentions
0No linked articles in our index yet.