Known Vulnerabilities for products from Iscripts
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Iscripts".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2018-11470 json | iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel. | 8.8 - HIGH | 2018-05-25 | 2018-06-27 |
| CVE-2018-11373 json | iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter. | 9.8 - CRITICAL | 2018-05-22 | 2018-06-25 |
| CVE-2018-11372 json | iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter. | 9.8 - CRITICAL | 2018-05-22 | 2018-06-25 |
| CVE-2018-10137 json | iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&actio... | 8.8 - HIGH | 2018-04-16 | 2018-05-22 |
| CVE-2018-10136 json | iScripts UberforX 2.2 has Stored XSS in the "manage_settings" section of the Admin Panel via a value field to the /cms?sectio... | 6.1 - MEDIUM | 2018-04-16 | 2018-05-21 |
| CVE-2018-10135 json | iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel. | 6.1 - MEDIUM | 2018-04-16 | 2018-05-17 |
| CVE-2018-10052 json | iScripts SupportDesk v4.3 has XSS via the admin/inteligentsearchresult.php txtinteligentsearch parameter. | 4.8 - MEDIUM | 2018-04-11 | 2018-05-09 |
| CVE-2018-10051 json | iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter. | 5.4 - MEDIUM | 2018-04-11 | 2018-05-09 |
| CVE-2018-10050 json | iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel. | 7.2 - HIGH | 2018-04-11 | 2018-05-09 |
| CVE-2018-10049 json | iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel. | 4.8 - MEDIUM | 2018-04-11 | 2018-05-09 |
| CVE-2018-10048 json | iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel. | 8.8 - HIGH | 2018-04-11 | 2018-05-09 |
| CVE-2018-9237 json | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field. | 5.4 - MEDIUM | 2018-04-04 | 2018-05-02 |
| CVE-2018-9236 json | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field. | 5.4 - MEDIUM | 2018-04-04 | 2018-05-02 |
| CVE-2018-9235 json | iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php. | 6.1 - MEDIUM | 2018-04-04 | 2018-05-02 |
| CVE-2013-7190 json | Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary f... | Not Provided | 2013-12-20 | 2026-04-29 |
| CVE-2013-7189 json | Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL ... | Not Provided | 2013-12-20 | 2026-04-29 |
| CVE-2010-5036 json | SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands vi... | Not Provided | 2011-11-02 | 2026-04-29 |
| CVE-2010-5035 json | Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web ... | Not Provided | 2011-11-02 | 2026-04-29 |
| CVE-2010-5034 json | SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary ... | Not Provided | 2011-11-02 | 2026-04-29 |
| CVE-2010-4983 json | SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL comman... | Not Provided | 2011-11-01 | 2026-04-29 |
Known software with vulnerabilities from Iscripts
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Iscripts | Autohoster | 2.4 |
| Application | Iscripts | Easybiller | 1.1 |
| Application | Iscripts | Easycreate | 3.2.1 |
| Application | Iscripts | Eswap | 2.0 |
| Application | Iscripts | Sonicbb | 1.0 |
| Application | Iscripts | Supportdesk | 4.3 |
| Application | Iscripts | Uberforx | 2.2 |