Show filters
32 Total Results
Displaying 11-20 of 32
Sort by:
Attacker Value
Unknown
CVE-2018-10050
Disclosure Date: April 11, 2018 (last updated November 26, 2024)
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
0
Attacker Value
Unknown
CVE-2018-9235
Disclosure Date: April 04, 2018 (last updated November 26, 2024)
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.
0
Attacker Value
Unknown
CVE-2018-9237
Disclosure Date: April 04, 2018 (last updated November 26, 2024)
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
0
Attacker Value
Unknown
CVE-2018-9236
Disclosure Date: April 04, 2018 (last updated November 26, 2024)
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.
0
Attacker Value
Unknown
CVE-2013-7189
Disclosure Date: December 20, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via the cmbdomain parameter to (1) checktransferstatus.php, (2) checktransferstatusbck.php, or (3) additionalsettings.php; or (4) invno parameter to payinvoiceothers.php.
0
Attacker Value
Unknown
CVE-2013-7190
Disclosure Date: December 20, 2013 (last updated October 05, 2023)
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the (1) tmpid parameter to websitebuilder/showtemplateimage.php, (2) fname parameter to admin/downloadfile.php, or (3) id parameter to support/admin/csvdownload.php; or (4) have an unspecified impact via unspecified vectors in support/parser/main_smtp.php.
0
Attacker Value
Unknown
CVE-2010-5035
Disclosure Date: November 02, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka the search field). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2010-5036
Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.
0
Attacker Value
Unknown
CVE-2010-5034
Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the planid parameter.
0
Attacker Value
Unknown
CVE-2010-4983
Disclosure Date: November 01, 2011 (last updated October 04, 2023)
SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0