« Volver al listado

Iscripts

Iscripts Eswap: vulnerabilidades y CVE

Iscripts Eswap tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses0
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2018-11470Alta (8.8)1.1%—25 may 2018
iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.
CVE-2018-11373Crítica (9.8)1.2%—22 may 2018
iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.
CVE-2018-11372Crítica (9.8)1.2%—22 may 2018
iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.
CVE-2018-10135Media (6.1)0.67%—16 abr 2018
iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.
CVE-2018-10050Alta (7.2)1.0%—11 abr 2018
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
CVE-2018-10049Media (4.8)0.53%—11 abr 2018
iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel.
CVE-2018-10048Alta (8.8)0.49%—11 abr 2018
iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.
CVE-2010-5036Alta (7.5)1.2%—2 nov 2011
SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.
CVE-2010-5035Media (4.3)1.8%—2 nov 2011
Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka the search field). NOTE: some of these…

Otros productos de Iscripts