Записи Iscripts
29 опубликованных записей вендора iscripts.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 10
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')15
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-310 Cryptographic Issues1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
29 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2018-11372Эксплойта нет | iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.iscripts · eswap · CWE-89 | Критическая9,8 | — | 1,2 % | 22 мая 2018 г. |
39Наблюдать | CVE-2018-11373Эксплойта нет | iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.iscripts · eswap · CWE-89 | Критическая9,8 | — | 1,2 % | 22 мая 2018 г. |
35Наблюдать | CVE-2018-11470Эксплойта нет | iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.iscripts · eswap · CWE-89 | Высокая8,8 | — | 1,1 % | 25 мая 2018 г. |
35Наблюдать | CVE-2018-10137Эксплойта нет | iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&action=edit URI.iscripts · uberforx · CWE-352 | Высокая8,8 | — | 0,5 % | 16 апр. 2018 г. |
35Наблюдать | CVE-2018-10048Эксплойта нет | iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.iscripts · eswap · CWE-352 | Высокая8,8 | — | 0,5 % | 11 апр. 2018 г. |
31Наблюдать | CVE-2010-4980Proof of concept | SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands viaiscripts · reservelogic · CWE-89 | Высокая7,5 | — | 2,4 % | 1 нояб. 2011 г. |
30Наблюдать | CVE-2013-7189Proof of concept | Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via thiscripts · autohoster · CWE-89 | Высокая7,5 | — | 1,3 % | 20 дек. 2013 г. |
30Наблюдать | CVE-2010-2853Proof of concept | SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arbitrary SQL commands iscripts · visualcaster · CWE-89 | Высокая7,5 | — | 1,2 % | 24 июл. 2010 г. |
30Наблюдать | CVE-2010-4983Proof of concept | SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id piscripts · cybermatch · CWE-89 | Высокая7,5 | — | 1,2 % | 1 нояб. 2011 г. |
30Наблюдать | CVE-2010-5036Proof of concept | SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type paraiscripts · eswap · CWE-89 | Высокая7,5 | — | 1,2 % | 2 нояб. 2011 г. |
30Наблюдать | CVE-2010-5034Proof of concept | SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands viiscripts · easybiller · CWE-89 | Высокая7,5 | — | 1,2 % | 2 нояб. 2011 г. |
30Наблюдать | CVE-2010-2624Proof of concept | Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) commeniscripts · easysnaps · CWE-89 | Высокая7,5 | — | 1,2 % | 2 июл. 2010 г. |
30Наблюдать | CVE-2008-1859Proof of concept | SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL commands via the id parameiscripts · socialware · CWE-89 | Высокая7,5 | — | 1,0 % | 16 апр. 2008 г. |
30Наблюдать | CVE-2008-4169Proof of concept | SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commandsiscripts · easyindex · CWE-89 | Высокая7,5 | — | 1,0 % | 22 сент. 2008 г. |
28Наблюдать | CVE-2018-10050Эксплойта нет | iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.iscripts · eswap · CWE-89 | Высокая7,2 | — | 1,0 % | 11 апр. 2018 г. |
26Наблюдать | CVE-2007-5261Proof of concept | Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameteriscripts · multicart · CWE-89 | Средняя6,4 | — | 2,0 % | 6 окт. 2007 г. |
26Наблюдать | CVE-2008-1790Proof of concept | Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a craiscripts · socialware · CWE-264 | Средняя6,5 | — | 1,1 % | 15 апр. 2008 г. |
26Наблюдать | CVE-2008-0911Proof of concept | SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commaiscripts · multicart · CWE-89 | Средняя6,5 | — | 0,9 % | 22 февр. 2008 г. |
25Наблюдать | CVE-2018-9235Proof of concept | iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.iscripts · sonicbb · CWE-79 | Средняя6,1 | — | 2,5 % | 4 апр. 2018 г. |
24Наблюдать | CVE-2018-10135Эксплойта нет | iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.iscripts · eswap · CWE-79 | Средняя6,1 | — | 0,7 % | 16 апр. 2018 г. |
24Наблюдать | CVE-2018-10136Эксплойта нет | iScripts UberforX 2.2 has Stored XSS in the "manage_settings" section of the Admin Panel via a value field to the /cms?section=manage_settiniscripts · uberforx · CWE-79 | Средняя6,1 | — | 0,7 % | 16 апр. 2018 г. |
22Наблюдать | CVE-2018-9237Proof of concept | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.iscripts · easycreate · CWE-79 | Средняя5,4 | — | 1,8 % | 4 апр. 2018 г. |
22Наблюдать | CVE-2018-9236Proof of concept | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.iscripts · easycreate · CWE-79 | Средняя5,4 | — | 1,8 % | 4 апр. 2018 г. |
21Наблюдать | CVE-2013-7190Proof of concept | Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the (1iscripts · autohoster · CWE-22 | Средняя5,0 | — | 3,8 % | 20 дек. 2013 г. |
21Наблюдать | CVE-2008-1772Proof of concept | iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sensitive information.iscripts · socialware · CWE-310 | Средняя5,0 | — | 2,5 % | 14 апр. 2008 г. |
- CVE-2018-1137239Наблюдать
iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %iscripts · eswap22 мая 2018 г.
- CVE-2018-1137339Наблюдать
iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %iscripts · eswap22 мая 2018 г.
- CVE-2018-1147035Наблюдать
iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %iscripts · eswap25 мая 2018 г.
- CVE-2018-1013735Наблюдать
iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&action=edit URI.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %iscripts · uberforx16 апр. 2018 г.
- CVE-2018-1004835Наблюдать
iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %iscripts · eswap11 апр. 2018 г.
- CVE-2010-498031Наблюдать
SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %iscripts · reservelogic1 нояб. 2011 г.
- CVE-2013-718930Наблюдать
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via th
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %iscripts · autohoster20 дек. 2013 г.
- CVE-2010-285330Наблюдать
SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %iscripts · visualcaster24 июл. 2010 г.
- CVE-2010-498330Наблюдать
SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id p
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %iscripts · cybermatch1 нояб. 2011 г.
- CVE-2010-503630Наблюдать
SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type para
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %iscripts · eswap2 нояб. 2011 г.
- CVE-2010-503430Наблюдать
SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands vi
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %iscripts · easybiller2 нояб. 2011 г.
- CVE-2010-262430Наблюдать
Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) commen
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %iscripts · easysnaps2 июл. 2010 г.
- CVE-2008-185930Наблюдать
SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL commands via the id parame
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %iscripts · socialware16 апр. 2008 г.
- CVE-2008-416930Наблюдать
SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %iscripts · easyindex22 сент. 2008 г.
- CVE-2018-1005028Наблюдать
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %iscripts · eswap11 апр. 2018 г.
- CVE-2007-526126Наблюдать
Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter
СредняяCVSS 6,4Proof of conceptEPSS 2 %iscripts · multicart6 окт. 2007 г.
- CVE-2008-179026Наблюдать
Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a cra
СредняяCVSS 6,5Proof of conceptEPSS 1 %iscripts · socialware15 апр. 2008 г.
- CVE-2008-091126Наблюдать
SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL comma
СредняяCVSS 6,5Proof of conceptEPSS 1 %iscripts · multicart22 февр. 2008 г.
- CVE-2018-923525Наблюдать
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.
СредняяCVSS 6,1Proof of conceptEPSS 2 %iscripts · sonicbb4 апр. 2018 г.
- CVE-2018-1013524Наблюдать
iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %iscripts · eswap16 апр. 2018 г.
- CVE-2018-1013624Наблюдать
iScripts UberforX 2.2 has Stored XSS in the "manage_settings" section of the Admin Panel via a value field to the /cms?section=manage_settin
СредняяCVSS 6,1Эксплойта нетEPSS 1 %iscripts · uberforx16 апр. 2018 г.
- CVE-2018-923722Наблюдать
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
СредняяCVSS 5,4Proof of conceptEPSS 2 %iscripts · easycreate4 апр. 2018 г.
- CVE-2018-923622Наблюдать
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.
СредняяCVSS 5,4Proof of conceptEPSS 2 %iscripts · easycreate4 апр. 2018 г.
- CVE-2013-719021Наблюдать
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the (1
СредняяCVSS 5,0Proof of conceptEPSS 4 %iscripts · autohoster20 дек. 2013 г.
- CVE-2008-177221Наблюдать
iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sensitive information.
СредняяCVSS 5,0Proof of conceptEPSS 2 %iscripts · socialware14 апр. 2008 г.