Show filters
32 Total Results
Displaying 11-20 of 32
Sort by:
Attacker Value
Unknown

CVE-2018-10050

Disclosure Date: April 11, 2018 (last updated November 26, 2024)
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
0
Attacker Value
Unknown

CVE-2018-9235

Disclosure Date: April 04, 2018 (last updated November 26, 2024)
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.
0
Attacker Value
Unknown

CVE-2018-9237

Disclosure Date: April 04, 2018 (last updated November 26, 2024)
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
0
Attacker Value
Unknown

CVE-2018-9236

Disclosure Date: April 04, 2018 (last updated November 26, 2024)
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.
0
Attacker Value
Unknown

CVE-2013-7189

Disclosure Date: December 20, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via the cmbdomain parameter to (1) checktransferstatus.php, (2) checktransferstatusbck.php, or (3) additionalsettings.php; or (4) invno parameter to payinvoiceothers.php.
0
Attacker Value
Unknown

CVE-2013-7190

Disclosure Date: December 20, 2013 (last updated October 05, 2023)
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the (1) tmpid parameter to websitebuilder/showtemplateimage.php, (2) fname parameter to admin/downloadfile.php, or (3) id parameter to support/admin/csvdownload.php; or (4) have an unspecified impact via unspecified vectors in support/parser/main_smtp.php.
0
Attacker Value
Unknown

CVE-2010-5035

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka the search field). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-5036

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.
0
Attacker Value
Unknown

CVE-2010-5034

Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the planid parameter.
0
Attacker Value
Unknown

CVE-2010-4983

Disclosure Date: November 01, 2011 (last updated October 04, 2023)
SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0