Vulnerabilities
14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-11470 | iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel. iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel. NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — | |
| CVE-2018-11373 +1 in the same advisory: …11372 | iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter. iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2018-10137 +1 in the same advisory: …10136 | iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&action=edit URI. iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&action=edit URI. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2018-10135 | iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel. iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2018-10051 +1 in the same advisory: …10052 | iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter. iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter. NVD description · AI analysis pending | 5.4 group max | <1% | PoC |
| — | |
| CVE-2018-10048 | iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel. iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2018-9237 +1 in the same advisory: …9236 | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field. iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field. NVD description · AI analysis pending | 5.4 | 2% | PoC ×2 |
| — | |
| CVE-2018-9235 | iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php. iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php. NVD description · AI analysis pending | 6.1 | 2% | PoC ×2 |
| — |