ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-11470
iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.

iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.

NVD description · AI analysis pending
8.81% PoC
  • iscripts eswap
CVE-2018-11373
+1 in the same advisory: …11372
iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.

iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.

NVD description · AI analysis pending
9.81% PoC
  • iscripts eswap
CVE-2018-10137
+1 in the same advisory: …10136
iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&action=edit URI.

iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&action=edit URI.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • iscripts uberforx
CVE-2018-10135
iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.

iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.

NVD description · AI analysis pending
6.1<1% PoC
  • iscripts eswap
CVE-2018-10051
+1 in the same advisory: …10052
iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter.

iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter.

NVD description · AI analysis pending
5.4
group max
<1% PoC
  • iscripts supportdesk
CVE-2018-10048
+2 in the same advisory: …10050 …10049
iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.

iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • iscripts eswap
CVE-2018-9237
+1 in the same advisory: …9236
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.

iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.

NVD description · AI analysis pending
5.42% PoC ×2
  • iscripts easycreate
CVE-2018-9235
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.

iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.

NVD description · AI analysis pending
6.12% PoC ×2
  • iscripts sonicbb