Iscripts records
29 published records for vendor iscripts.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 10
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')15
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-310 Cryptographic Issues1
The weakness classes this vendor ships most often: where to look.
CWEAll records
29 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2018-11372No exploit | iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.iscripts · eswap · CWE-89 | Critical9.8 | — | 1.2% | May 22, 2018 |
39Monitor | CVE-2018-11373No exploit | iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.iscripts · eswap · CWE-89 | Critical9.8 | — | 1.2% | May 22, 2018 |
35Monitor | CVE-2018-11470No exploit | iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.iscripts · eswap · CWE-89 | High8.8 | — | 1.1% | May 25, 2018 |
35Monitor | CVE-2018-10137No exploit | iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&action=edit URI.iscripts · uberforx · CWE-352 | High8.8 | — | 0.5% | Apr 16, 2018 |
35Monitor | CVE-2018-10048No exploit | iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.iscripts · eswap · CWE-352 | High8.8 | — | 0.5% | Apr 11, 2018 |
31Monitor | CVE-2010-4980Proof of concept | SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands viaiscripts · reservelogic · CWE-89 | High7.5 | — | 2.4% | Nov 1, 2011 |
30Monitor | CVE-2013-7189Proof of concept | Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via thiscripts · autohoster · CWE-89 | High7.5 | — | 1.3% | Dec 20, 2013 |
30Monitor | CVE-2010-2853Proof of concept | SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arbitrary SQL commands iscripts · visualcaster · CWE-89 | High7.5 | — | 1.2% | Jul 24, 2010 |
30Monitor | CVE-2010-4983Proof of concept | SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id piscripts · cybermatch · CWE-89 | High7.5 | — | 1.2% | Nov 1, 2011 |
30Monitor | CVE-2010-5036Proof of concept | SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type paraiscripts · eswap · CWE-89 | High7.5 | — | 1.2% | Nov 2, 2011 |
30Monitor | CVE-2010-5034Proof of concept | SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands viiscripts · easybiller · CWE-89 | High7.5 | — | 1.2% | Nov 2, 2011 |
30Monitor | CVE-2010-2624Proof of concept | Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) commeniscripts · easysnaps · CWE-89 | High7.5 | — | 1.2% | Jul 2, 2010 |
30Monitor | CVE-2008-1859Proof of concept | SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL commands via the id parameiscripts · socialware · CWE-89 | High7.5 | — | 1.0% | Apr 16, 2008 |
30Monitor | CVE-2008-4169Proof of concept | SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commandsiscripts · easyindex · CWE-89 | High7.5 | — | 1.0% | Sep 22, 2008 |
28Monitor | CVE-2018-10050No exploit | iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.iscripts · eswap · CWE-89 | High7.2 | — | 1.0% | Apr 11, 2018 |
26Monitor | CVE-2007-5261Proof of concept | Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameteriscripts · multicart · CWE-89 | Medium6.4 | — | 2.0% | Oct 6, 2007 |
26Monitor | CVE-2008-1790Proof of concept | Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a craiscripts · socialware · CWE-264 | Medium6.5 | — | 1.1% | Apr 15, 2008 |
26Monitor | CVE-2008-0911Proof of concept | SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commaiscripts · multicart · CWE-89 | Medium6.5 | — | 0.9% | Feb 22, 2008 |
25Monitor | CVE-2018-9235Proof of concept | iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.iscripts · sonicbb · CWE-79 | Medium6.1 | — | 2.5% | Apr 4, 2018 |
24Monitor | CVE-2018-10135No exploit | iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.iscripts · eswap · CWE-79 | Medium6.1 | — | 0.7% | Apr 16, 2018 |
24Monitor | CVE-2018-10136No exploit | iScripts UberforX 2.2 has Stored XSS in the "manage_settings" section of the Admin Panel via a value field to the /cms?section=manage_settiniscripts · uberforx · CWE-79 | Medium6.1 | — | 0.7% | Apr 16, 2018 |
22Monitor | CVE-2018-9237Proof of concept | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.iscripts · easycreate · CWE-79 | Medium5.4 | — | 1.8% | Apr 4, 2018 |
22Monitor | CVE-2018-9236Proof of concept | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.iscripts · easycreate · CWE-79 | Medium5.4 | — | 1.8% | Apr 4, 2018 |
21Monitor | CVE-2013-7190Proof of concept | Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the (1iscripts · autohoster · CWE-22 | Medium5.0 | — | 3.8% | Dec 20, 2013 |
21Monitor | CVE-2008-1772Proof of concept | iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sensitive information.iscripts · socialware · CWE-310 | Medium5.0 | — | 2.5% | Apr 14, 2008 |
- CVE-2018-1137239Monitor
iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.
CriticalCVSS 9.8No exploitEPSS 1%iscripts · eswapMay 22, 2018
- CVE-2018-1137339Monitor
iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.
CriticalCVSS 9.8No exploitEPSS 1%iscripts · eswapMay 22, 2018
- CVE-2018-1147035Monitor
iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.
HighCVSS 8.8No exploitEPSS 1%iscripts · eswapMay 25, 2018
- CVE-2018-1013735Monitor
iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&action=edit URI.
HighCVSS 8.8No exploitEPSS 0%iscripts · uberforxApr 16, 2018
- CVE-2018-1004835Monitor
iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.
HighCVSS 8.8No exploitEPSS 0%iscripts · eswapApr 11, 2018
- CVE-2010-498031Monitor
SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 2%iscripts · reservelogicNov 1, 2011
- CVE-2013-718930Monitor
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via th
HighCVSS 7.5Proof of conceptEPSS 1%iscripts · autohosterDec 20, 2013
- CVE-2010-285330Monitor
SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5Proof of conceptEPSS 1%iscripts · visualcasterJul 24, 2010
- CVE-2010-498330Monitor
SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id p
HighCVSS 7.5Proof of conceptEPSS 1%iscripts · cybermatchNov 1, 2011
- CVE-2010-503630Monitor
SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type para
HighCVSS 7.5Proof of conceptEPSS 1%iscripts · eswapNov 2, 2011
- CVE-2010-503430Monitor
SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands vi
HighCVSS 7.5Proof of conceptEPSS 1%iscripts · easybillerNov 2, 2011
- CVE-2010-262430Monitor
Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) commen
HighCVSS 7.5Proof of conceptEPSS 1%iscripts · easysnapsJul 2, 2010
- CVE-2008-185930Monitor
SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL commands via the id parame
HighCVSS 7.5Proof of conceptEPSS 1%iscripts · socialwareApr 16, 2008
- CVE-2008-416930Monitor
SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5Proof of conceptEPSS 1%iscripts · easyindexSep 22, 2008
- CVE-2018-1005028Monitor
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
HighCVSS 7.2No exploitEPSS 1%iscripts · eswapApr 11, 2018
- CVE-2007-526126Monitor
Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter
MediumCVSS 6.4Proof of conceptEPSS 2%iscripts · multicartOct 6, 2007
- CVE-2008-179026Monitor
Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a cra
MediumCVSS 6.5Proof of conceptEPSS 1%iscripts · socialwareApr 15, 2008
- CVE-2008-091126Monitor
SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL comma
MediumCVSS 6.5Proof of conceptEPSS 1%iscripts · multicartFeb 22, 2008
- CVE-2018-923525Monitor
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.
MediumCVSS 6.1Proof of conceptEPSS 2%iscripts · sonicbbApr 4, 2018
- CVE-2018-1013524Monitor
iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.
MediumCVSS 6.1No exploitEPSS 1%iscripts · eswapApr 16, 2018
- CVE-2018-1013624Monitor
iScripts UberforX 2.2 has Stored XSS in the "manage_settings" section of the Admin Panel via a value field to the /cms?section=manage_settin
MediumCVSS 6.1No exploitEPSS 1%iscripts · uberforxApr 16, 2018
- CVE-2018-923722Monitor
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
MediumCVSS 5.4Proof of conceptEPSS 2%iscripts · easycreateApr 4, 2018
- CVE-2018-923622Monitor
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.
MediumCVSS 5.4Proof of conceptEPSS 2%iscripts · easycreateApr 4, 2018
- CVE-2013-719021Monitor
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the (1
MediumCVSS 5.0Proof of conceptEPSS 4%iscripts · autohosterDec 20, 2013
- CVE-2008-177221Monitor
iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sensitive information.
MediumCVSS 5.0Proof of conceptEPSS 2%iscripts · socialwareApr 14, 2008