Записи itechscripts
24 опубликованных записей вендора itechscripts.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')17
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
24 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-15963Proof of concept | iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.itechscripts · gigs script · CWE-89 | Критическая9,8 | — | 2,1 % | 29 окт. 2017 г. |
39Наблюдать | CVE-2017-20130Эксплойта нет | Itech Real Estate Script search_property.php sql injectionitechscripts · real estate script · CWE-89 | Критическая9,8 | — | 1,0 % | 16 июл. 2022 г. |
39Наблюдать | CVE-2017-20131Эксплойта нет | Itech News Portal information.php sql injectionitechscripts · news portal script · CWE-89 | Критическая9,8 | — | 1,0 % | 16 июл. 2022 г. |
39Наблюдать | CVE-2017-20135Эксплойта нет | Itech Dating Script see_more_details.php sql injectionitechscripts · dating script · CWE-89 | Критическая9,8 | — | 1,0 % | 16 июл. 2022 г. |
39Наблюдать | CVE-2017-20134Эксплойта нет | Itech Freelancer Script category.php sql injectionitechscripts · freelancer script · CWE-89 | Критическая9,8 | — | 0,9 % | 16 июл. 2022 г. |
39Наблюдать | CVE-2017-20132Эксплойта нет | Itech Multi Vendor Script product-list.php sql injectionitechscripts · multi vendor script · CWE-89 | Критическая9,8 | — | 0,9 % | 16 июл. 2022 г. |
39Наблюдать | CVE-2017-20133Эксплойта нет | Itech Job Portal Script admin improper authenticationitechscripts · job portal script · CWE-287 | Критическая9,8 | — | 0,7 % | 16 июл. 2022 г. |
39Наблюдать | CVE-2017-20138Эксплойта нет | Itech Auction Script mcategory.php Blind sql injectionitechscripts · auction script · CWE-89 | Критическая9,8 | — | 0,6 % | 16 июл. 2022 г. |
31Наблюдать | CVE-2012-4281Proof of concept | Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid parameitechscripts · travelon express · CWE-89 | Высокая7,5 | — | 2,2 % | 13 авг. 2012 г. |
30Наблюдать | CVE-2014-100020Proof of concept | SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via thitechscripts · itechclassifieds · CWE-89 | Высокая7,5 | — | 1,3 % | 13 янв. 2015 г. |
30Наблюдать | CVE-2008-3238Proof of concept | Multiple SQL injection vulnerabilities in ITechBids 7.0 Gold allow remote attackers to execute arbitrary SQL commands via (1) the seller_id itechscripts · itechbids · CWE-89 | Высокая7,5 | — | 1,2 % | 21 июл. 2008 г. |
30Наблюдать | CVE-2008-0776Proof of concept | SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL commands via the item_id paitechscripts · itechbids · CWE-89 | Высокая7,5 | — | 1,1 % | 13 февр. 2008 г. |
30Наблюдать | CVE-2012-4265Proof of concept | SQL injection vulnerability in category_edit.php in Proman Xpress 5.0.1 allows remote attackers to execute arbitrary SQL commands via the ciitechscripts · proman xpress · CWE-89 | Высокая7,5 | — | 1,0 % | 13 авг. 2012 г. |
30Наблюдать | CVE-2008-0692Proof of concept | SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary SQL commands via the itechscripts · itechbids · CWE-89 | Высокая7,5 | — | 1,0 % | 11 февр. 2008 г. |
30Наблюдать | CVE-2008-0685Proof of concept | SQL injection vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to execute arbitrary SQL commands via the CatID pitechscripts · itechclassifieds · CWE-89 | Высокая7,5 | — | 1,0 % | 11 февр. 2008 г. |
30Наблюдать | CVE-2009-3968Proof of concept | Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parametitechscripts · itechbids · CWE-89 | Высокая7,5 | — | 0,9 % | 18 нояб. 2009 г. |
30Наблюдать | CVE-2017-20136Эксплойта нет | Itech Classifieds Script subpage.php sql injectionitechscripts · classifieds script · CWE-89 | Высокая7,5 | — | 0,7 % | 16 июл. 2022 г. |
30Наблюдать | CVE-2017-20137Эксплойта нет | Itech B2B Script catcompany.php sql injectionitechscripts · b2b script · CWE-89 | Высокая7,5 | — | 0,7 % | 16 июл. 2022 г. |
27Наблюдать | CVE-2012-2939Proof of concept | Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by upitechscripts · travelon express | Средняя6,5 | — | 3,9 % | 27 мая 2012 г. |
18Наблюдать | CVE-2012-2938Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary web script or HTML itechscripts · travelon express · CWE-79 | Средняя4,3 | — | 1,8 % | 27 мая 2012 г. |
18Наблюдать | CVE-2008-3237Proof of concept | Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to inject arbitrary web scriitechscripts · itechbids · CWE-79 | Средняя4,3 | — | 1,7 % | 21 июл. 2008 г. |
17Наблюдать | CVE-2012-4266Proof of concept | Cross-site scripting (XSS) vulnerability in client_details.php in Proman Xpress 5.0.1 allows remote attackers to inject arbitrary web scriptitechscripts · proman xpress · CWE-79 | Средняя4,3 | — | 1,6 % | 13 авг. 2012 г. |
17Наблюдать | CVE-2008-0684Proof of concept | Cross-site scripting (XSS) vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to inject arbitrary web script or HTitechscripts · itechclassifieds · CWE-79 | Средняя4,3 | — | 1,4 % | 11 февр. 2008 г. |
17Наблюдать | CVE-2008-4872Эксплойта нет | Cross-site scripting (XSS) vulnerability in bidhistory.php in iTechBids Gold 5.0 allows remote attackers to inject arbitrary web script or Hitechscripts · itechbids · CWE-79 | Средняя4,3 | — | 0,8 % | 31 окт. 2008 г. |
- CVE-2017-1596340В плане
iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.
КритическаяCVSS 9,8Proof of conceptEPSS 2 %itechscripts · gigs script29 окт. 2017 г.
- CVE-2017-2013039Наблюдать
Itech Real Estate Script search_property.php sql injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %itechscripts · real estate script16 июл. 2022 г.
- CVE-2017-2013139Наблюдать
Itech News Portal information.php sql injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %itechscripts · news portal script16 июл. 2022 г.
- CVE-2017-2013539Наблюдать
Itech Dating Script see_more_details.php sql injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %itechscripts · dating script16 июл. 2022 г.
- CVE-2017-2013439Наблюдать
Itech Freelancer Script category.php sql injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %itechscripts · freelancer script16 июл. 2022 г.
- CVE-2017-2013239Наблюдать
Itech Multi Vendor Script product-list.php sql injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %itechscripts · multi vendor script16 июл. 2022 г.
- CVE-2017-2013339Наблюдать
Itech Job Portal Script admin improper authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %itechscripts · job portal script16 июл. 2022 г.
- CVE-2017-2013839Наблюдать
Itech Auction Script mcategory.php Blind sql injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %itechscripts · auction script16 июл. 2022 г.
- CVE-2012-428131Наблюдать
Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid parame
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %itechscripts · travelon express13 авг. 2012 г.
- CVE-2014-10002030Наблюдать
SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via th
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %itechscripts · itechclassifieds13 янв. 2015 г.
- CVE-2008-323830Наблюдать
Multiple SQL injection vulnerabilities in ITechBids 7.0 Gold allow remote attackers to execute arbitrary SQL commands via (1) the seller_id
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %itechscripts · itechbids21 июл. 2008 г.
- CVE-2008-077630Наблюдать
SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL commands via the item_id pa
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %itechscripts · itechbids13 февр. 2008 г.
- CVE-2012-426530Наблюдать
SQL injection vulnerability in category_edit.php in Proman Xpress 5.0.1 allows remote attackers to execute arbitrary SQL commands via the ci
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %itechscripts · proman xpress13 авг. 2012 г.
- CVE-2008-069230Наблюдать
SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary SQL commands via the
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %itechscripts · itechbids11 февр. 2008 г.
- CVE-2008-068530Наблюдать
SQL injection vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to execute arbitrary SQL commands via the CatID p
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %itechscripts · itechclassifieds11 февр. 2008 г.
- CVE-2009-396830Наблюдать
Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) user_id paramet
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %itechscripts · itechbids18 нояб. 2009 г.
- CVE-2017-2013630Наблюдать
Itech Classifieds Script subpage.php sql injection
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %itechscripts · classifieds script16 июл. 2022 г.
- CVE-2017-2013730Наблюдать
Itech B2B Script catcompany.php sql injection
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %itechscripts · b2b script16 июл. 2022 г.
- CVE-2012-293927Наблюдать
Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by up
СредняяCVSS 6,5Proof of conceptEPSS 4 %itechscripts · travelon express27 мая 2012 г.
- CVE-2012-293818Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Proof of conceptEPSS 2 %itechscripts · travelon express27 мая 2012 г.
- CVE-2008-323718Наблюдать
Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to inject arbitrary web scri
СредняяCVSS 4,3Proof of conceptEPSS 2 %itechscripts · itechbids21 июл. 2008 г.
- CVE-2012-426617Наблюдать
Cross-site scripting (XSS) vulnerability in client_details.php in Proman Xpress 5.0.1 allows remote attackers to inject arbitrary web script
СредняяCVSS 4,3Proof of conceptEPSS 2 %itechscripts · proman xpress13 авг. 2012 г.
- CVE-2008-068417Наблюдать
Cross-site scripting (XSS) vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to inject arbitrary web script or HT
СредняяCVSS 4,3Proof of conceptEPSS 1 %itechscripts · itechclassifieds11 февр. 2008 г.
- CVE-2008-487217Наблюдать
Cross-site scripting (XSS) vulnerability in bidhistory.php in iTechBids Gold 5.0 allows remote attackers to inject arbitrary web script or H
СредняяCVSS 4,3Эксплойта нетEPSS 1 %itechscripts · itechbids31 окт. 2008 г.