Skip to content
Noroxi

ectouch records

4 published records for vendor ectouch.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 21
  2. 22
  3. 23

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

4 records
  • ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    ectouch · ectouchAug 28, 2023

  • SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php..

    CriticalCVSS 9.8No exploitEPSS 1%

    ectouch · ectouchJul 30, 2021

  • SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    ectouch · ectouchJul 14, 2021

  • ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter.

    CriticalCVSS 9.1No exploitEPSS 1%

    ectouch · ectouchFeb 24, 2022