itechscripts records
24 published records for vendor itechscripts.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')17
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-15963Proof of concept | iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.itechscripts · gigs script · CWE-89 | Critical9.8 | — | 2.1% | Oct 29, 2017 |
39Monitor | CVE-2017-20130No exploit | Itech Real Estate Script search_property.php sql injectionitechscripts · real estate script · CWE-89 | Critical9.8 | — | 1.0% | Jul 16, 2022 |
39Monitor | CVE-2017-20131No exploit | Itech News Portal information.php sql injectionitechscripts · news portal script · CWE-89 | Critical9.8 | — | 1.0% | Jul 16, 2022 |
39Monitor | CVE-2017-20135No exploit | Itech Dating Script see_more_details.php sql injectionitechscripts · dating script · CWE-89 | Critical9.8 | — | 1.0% | Jul 16, 2022 |
39Monitor | CVE-2017-20134No exploit | Itech Freelancer Script category.php sql injectionitechscripts · freelancer script · CWE-89 | Critical9.8 | — | 0.9% | Jul 16, 2022 |
39Monitor | CVE-2017-20132No exploit | Itech Multi Vendor Script product-list.php sql injectionitechscripts · multi vendor script · CWE-89 | Critical9.8 | — | 0.9% | Jul 16, 2022 |
39Monitor | CVE-2017-20133No exploit | Itech Job Portal Script admin improper authenticationitechscripts · job portal script · CWE-287 | Critical9.8 | — | 0.7% | Jul 16, 2022 |
39Monitor | CVE-2017-20138No exploit | Itech Auction Script mcategory.php Blind sql injectionitechscripts · auction script · CWE-89 | Critical9.8 | — | 0.6% | Jul 16, 2022 |
31Monitor | CVE-2012-4281Proof of concept | Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid parameitechscripts · travelon express · CWE-89 | High7.5 | — | 2.2% | Aug 13, 2012 |
30Monitor | CVE-2014-100020Proof of concept | SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via thitechscripts · itechclassifieds · CWE-89 | High7.5 | — | 1.3% | Jan 13, 2015 |
30Monitor | CVE-2008-3238Proof of concept | Multiple SQL injection vulnerabilities in ITechBids 7.0 Gold allow remote attackers to execute arbitrary SQL commands via (1) the seller_id itechscripts · itechbids · CWE-89 | High7.5 | — | 1.2% | Jul 21, 2008 |
30Monitor | CVE-2008-0776Proof of concept | SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL commands via the item_id paitechscripts · itechbids · CWE-89 | High7.5 | — | 1.1% | Feb 13, 2008 |
30Monitor | CVE-2012-4265Proof of concept | SQL injection vulnerability in category_edit.php in Proman Xpress 5.0.1 allows remote attackers to execute arbitrary SQL commands via the ciitechscripts · proman xpress · CWE-89 | High7.5 | — | 1.0% | Aug 13, 2012 |
30Monitor | CVE-2008-0692Proof of concept | SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary SQL commands via the itechscripts · itechbids · CWE-89 | High7.5 | — | 1.0% | Feb 11, 2008 |
30Monitor | CVE-2008-0685Proof of concept | SQL injection vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to execute arbitrary SQL commands via the CatID pitechscripts · itechclassifieds · CWE-89 | High7.5 | — | 1.0% | Feb 11, 2008 |
30Monitor | CVE-2009-3968Proof of concept | Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parametitechscripts · itechbids · CWE-89 | High7.5 | — | 0.9% | Nov 18, 2009 |
30Monitor | CVE-2017-20136No exploit | Itech Classifieds Script subpage.php sql injectionitechscripts · classifieds script · CWE-89 | High7.5 | — | 0.7% | Jul 16, 2022 |
30Monitor | CVE-2017-20137No exploit | Itech B2B Script catcompany.php sql injectionitechscripts · b2b script · CWE-89 | High7.5 | — | 0.7% | Jul 16, 2022 |
27Monitor | CVE-2012-2939Proof of concept | Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by upitechscripts · travelon express | Medium6.5 | — | 3.9% | May 27, 2012 |
18Monitor | CVE-2012-2938Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary web script or HTML itechscripts · travelon express · CWE-79 | Medium4.3 | — | 1.8% | May 27, 2012 |
18Monitor | CVE-2008-3237Proof of concept | Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to inject arbitrary web scriitechscripts · itechbids · CWE-79 | Medium4.3 | — | 1.7% | Jul 21, 2008 |
17Monitor | CVE-2012-4266Proof of concept | Cross-site scripting (XSS) vulnerability in client_details.php in Proman Xpress 5.0.1 allows remote attackers to inject arbitrary web scriptitechscripts · proman xpress · CWE-79 | Medium4.3 | — | 1.6% | Aug 13, 2012 |
17Monitor | CVE-2008-0684Proof of concept | Cross-site scripting (XSS) vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to inject arbitrary web script or HTitechscripts · itechclassifieds · CWE-79 | Medium4.3 | — | 1.4% | Feb 11, 2008 |
17Monitor | CVE-2008-4872No exploit | Cross-site scripting (XSS) vulnerability in bidhistory.php in iTechBids Gold 5.0 allows remote attackers to inject arbitrary web script or Hitechscripts · itechbids · CWE-79 | Medium4.3 | — | 0.8% | Oct 31, 2008 |
- CVE-2017-1596340Plan
iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.
CriticalCVSS 9.8Proof of conceptEPSS 2%itechscripts · gigs scriptOct 29, 2017
- CVE-2017-2013039Monitor
Itech Real Estate Script search_property.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%itechscripts · real estate scriptJul 16, 2022
- CVE-2017-2013139Monitor
Itech News Portal information.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%itechscripts · news portal scriptJul 16, 2022
- CVE-2017-2013539Monitor
Itech Dating Script see_more_details.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%itechscripts · dating scriptJul 16, 2022
- CVE-2017-2013439Monitor
Itech Freelancer Script category.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%itechscripts · freelancer scriptJul 16, 2022
- CVE-2017-2013239Monitor
Itech Multi Vendor Script product-list.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%itechscripts · multi vendor scriptJul 16, 2022
- CVE-2017-2013339Monitor
Itech Job Portal Script admin improper authentication
CriticalCVSS 9.8No exploitEPSS 1%itechscripts · job portal scriptJul 16, 2022
- CVE-2017-2013839Monitor
Itech Auction Script mcategory.php Blind sql injection
CriticalCVSS 9.8No exploitEPSS 1%itechscripts · auction scriptJul 16, 2022
- CVE-2012-428131Monitor
Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid parame
HighCVSS 7.5Proof of conceptEPSS 2%itechscripts · travelon expressAug 13, 2012
- CVE-2014-10002030Monitor
SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via th
HighCVSS 7.5Proof of conceptEPSS 1%itechscripts · itechclassifiedsJan 13, 2015
- CVE-2008-323830Monitor
Multiple SQL injection vulnerabilities in ITechBids 7.0 Gold allow remote attackers to execute arbitrary SQL commands via (1) the seller_id
HighCVSS 7.5Proof of conceptEPSS 1%itechscripts · itechbidsJul 21, 2008
- CVE-2008-077630Monitor
SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL commands via the item_id pa
HighCVSS 7.5Proof of conceptEPSS 1%itechscripts · itechbidsFeb 13, 2008
- CVE-2012-426530Monitor
SQL injection vulnerability in category_edit.php in Proman Xpress 5.0.1 allows remote attackers to execute arbitrary SQL commands via the ci
HighCVSS 7.5Proof of conceptEPSS 1%itechscripts · proman xpressAug 13, 2012
- CVE-2008-069230Monitor
SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5Proof of conceptEPSS 1%itechscripts · itechbidsFeb 11, 2008
- CVE-2008-068530Monitor
SQL injection vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to execute arbitrary SQL commands via the CatID p
HighCVSS 7.5Proof of conceptEPSS 1%itechscripts · itechclassifiedsFeb 11, 2008
- CVE-2009-396830Monitor
Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) user_id paramet
HighCVSS 7.5Proof of conceptEPSS 1%itechscripts · itechbidsNov 18, 2009
- CVE-2017-2013630Monitor
Itech Classifieds Script subpage.php sql injection
HighCVSS 7.5No exploitEPSS 1%itechscripts · classifieds scriptJul 16, 2022
- CVE-2017-2013730Monitor
Itech B2B Script catcompany.php sql injection
HighCVSS 7.5No exploitEPSS 1%itechscripts · b2b scriptJul 16, 2022
- CVE-2012-293927Monitor
Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by up
MediumCVSS 6.5Proof of conceptEPSS 4%itechscripts · travelon expressMay 27, 2012
- CVE-2012-293818Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3Proof of conceptEPSS 2%itechscripts · travelon expressMay 27, 2012
- CVE-2008-323718Monitor
Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to inject arbitrary web scri
MediumCVSS 4.3Proof of conceptEPSS 2%itechscripts · itechbidsJul 21, 2008
- CVE-2012-426617Monitor
Cross-site scripting (XSS) vulnerability in client_details.php in Proman Xpress 5.0.1 allows remote attackers to inject arbitrary web script
MediumCVSS 4.3Proof of conceptEPSS 2%itechscripts · proman xpressAug 13, 2012
- CVE-2008-068417Monitor
Cross-site scripting (XSS) vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to inject arbitrary web script or HT
MediumCVSS 4.3Proof of conceptEPSS 1%itechscripts · itechclassifiedsFeb 11, 2008
- CVE-2008-487217Monitor
Cross-site scripting (XSS) vulnerability in bidhistory.php in iTechBids Gold 5.0 allows remote attackers to inject arbitrary web script or H
MediumCVSS 4.3No exploitEPSS 1%itechscripts · itechbidsOct 31, 2008