ectouch records
4 published records for vendor ectouch.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2023-39560Proof of concept | ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.ectouch · ectouch · CWE-89 | Critical9.8 | — | 4.7% | Aug 28, 2023 |
39Monitor | CVE-2020-21806No exploit | SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php..ectouch · ectouch · CWE-89 | Critical9.8 | — | 1.2% | Jul 30, 2021 |
39Monitor | CVE-2020-18144No exploit | SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php.ectouch · ectouch · CWE-89 | Critical9.8 | — | 1.1% | Jul 14, 2021 |
36Monitor | CVE-2022-25098No exploit | ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter.ectouch · ectouch | Critical9.1 | — | 1.0% | Feb 24, 2022 |
- CVE-2023-3956040Plan
ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.
CriticalCVSS 9.8Proof of conceptEPSS 5%ectouch · ectouchAug 28, 2023
- CVE-2020-2180639Monitor
SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php..
CriticalCVSS 9.8No exploitEPSS 1%ectouch · ectouchJul 30, 2021
- CVE-2020-1814439Monitor
SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php.
CriticalCVSS 9.8No exploitEPSS 1%ectouch · ectouchJul 14, 2021
- CVE-2022-2509836Monitor
ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter.
CriticalCVSS 9.1No exploitEPSS 1%ectouch · ectouchFeb 24, 2022