Session fixation vulnerability in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to hijack web sessions via unspecified vectors.
http://www.ec-cube.net/info/weakness/weakness.php?id=40
http://svn.ec-cube.net/open_trac/changeset/22805
http://svn.ec-cube.net/open_trac/changeset/22804