Known Vulnerabilities for Eswap by Iscripts
Listed below are 9 of the newest known vulnerabilities associated with "Eswap" by "Iscripts".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2018-11470 json | iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel. | 8.8 - HIGH | 2018-05-25 | 2018-06-27 |
| CVE-2018-11373 json | iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter. | 9.8 - CRITICAL | 2018-05-22 | 2018-06-25 |
| CVE-2018-11372 json | iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter. | 9.8 - CRITICAL | 2018-05-22 | 2018-06-25 |
| CVE-2018-10135 json | iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel. | 6.1 - MEDIUM | 2018-04-16 | 2018-05-17 |
| CVE-2018-10050 json | iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel. | 7.2 - HIGH | 2018-04-11 | 2018-05-09 |
| CVE-2018-10049 json | iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel. | 4.8 - MEDIUM | 2018-04-11 | 2018-05-09 |
| CVE-2018-10048 json | iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel. | 8.8 - HIGH | 2018-04-11 | 2018-05-09 |
| CVE-2010-5036 json | Not Provided | 2011-11-02 | 2026-04-29 | |
| CVE-2010-5035 json | Not Provided | 2011-11-02 | 2026-04-29 |