Vulnerability index

Browse CVEs

26 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2018-11470 iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel. Eswap No fix yet Fix from $1,9502018-05-25 CRITICAL 9.8 CVE-2018-11372 iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter. Eswap No fix yet Fix from $2,3002018-05-22 CRITICAL 9.8 CVE-2018-11373 iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter. Eswap No fix yet Fix from $2,3002018-05-22 HIGH 8.8 CVE-2018-10137 iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&action=edit URI. Uberforx No fix yet Fix from $1,9502018-04-16 MEDIUM 6.1 CVE-2018-10135 iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel. Eswap No fix yet Fix from $1,6002018-04-16 MEDIUM 6.1 CVE-2018-10136 iScripts UberforX 2.2 has Stored XSS in the "manage_settings" section of the Admin Panel via a value field to the /cms?section=manage_settings&action… Uberforx No fix yet Fix from $1,6002018-04-16 HIGH 8.8 CVE-2018-10048 iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel. Eswap No fix yet Fix from $1,9502018-04-11 HIGH 7.2 CVE-2018-10050 iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel. Eswap No fix yet Fix from $1,9502018-04-11 MEDIUM 5.4 CVE-2018-10051 iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter. Supportdesk No fix yet Fix from $1,6002018-04-11 MEDIUM 6.1 CVE-2018-9235 iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php. Sonicbb No fix yet Fix from $1,6002018-04-04 MEDIUM 5.4 CVE-2018-9236 iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field. Easycreate No fix yet Fix from $1,6002018-04-04 MEDIUM 5.4 CVE-2018-9237 iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field. Easycreate No fix yet Fix from $1,6002018-04-04 HIGH 7.5 CVE-2013-7189 Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via the cmbdoma… Autohoster Mitigation only Fix from $1,9502013-12-20 MEDIUM 5.0 CVE-2013-7190 Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the (1) tmpid p… Autohoster Mitigation only Fix from $1,6002013-12-20 HIGH 7.5 CVE-2010-5034 SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the pla… Easybiller No fix yet Fix from $1,9502011-11-02 HIGH 7.5 CVE-2010-5036 SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. Eswap No fix yet Fix from $1,9502011-11-02 HIGH 7.5 CVE-2010-4983 SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. Cybermatch No fix yet Fix from $1,9502011-11-01 HIGH 7.5 CVE-2010-4980 SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid … Reservelogic No fix yet Fix from $1,9502011-11-01 HIGH 7.5 CVE-2010-2853 SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arbitrary SQL commands via the p… Visualcaster No fix yet Fix from $1,9502010-07-25 HIGH 7.5 CVE-2010-2624 Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment paramet… Easysnaps No fix yet Fix from $1,9502010-07-02 HIGH 7.5 CVE-2008-4169 SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commands via the … Easyindex No fix yet Fix from $1,9502008-09-22 HIGH 7.5 CVE-2008-1859 SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL commands via the id parameter in a … Socialware No fix yet Fix from $1,9502008-04-16 MEDIUM 6.5 CVE-2008-1790 Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a crafted logo… Socialware No fix yet Fix from $1,6002008-04-15 MEDIUM 5.0 CVE-2008-1772 iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sensitive information. Socialware No fix yet Fix from $1,6002008-04-14 MEDIUM 6.5 CVE-2008-0911 SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via t… Multicart No fix yet Fix from $1,6002008-02-22 MEDIUM 6.4 CVE-2007-5261 Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to categ… Multicart No fix yet Fix from $1,6002007-10-06