Eswap
Vendor:
First CVE: Nov 2, 2011 · Active for 14 years
9
Total CVEs
More Total CVEs than 86% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Eswap over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 2, 2011
14 years ago
Most Recent CVE
May 25, 2018
2,983 days ago
CVE Severity & Scoring
Eswap9 CVEs
33%
44%
22%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (77.8%)
Unknown2 (22.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (77.8%)
High0 (0.0%)
Unknown2 (22.2%)
User Interaction
None4 (44.4%)
Unknown2 (22.2%)
Required3 (33.3%)
Privileges Required
Low1 (11.1%)
High2 (22.2%)
None4 (44.4%)
Unknown2 (22.2%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-5036HIGH SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. | Nov 2, 2011 | 7.5 | 32 | NO | YES |
CVE-2018-11373CRITICAL iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter. | May 22, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-11372CRITICAL iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter. | May 22, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-11470HIGH iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel. | May 25, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-10048HIGH iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel. | Apr 11, 2018 | 8.8 | 24 | NO | NO |
CVE-2018-10050HIGH iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel. | Apr 11, 2018 | 7.2 | 22 | NO | NO |
CVE-2010-5035MEDIUM Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka the | Nov 2, 2011 | 4.3 | 22 | NO | YES |
CVE-2018-10135MEDIUM iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel. | Apr 16, 2018 | 6.1 | 17 | NO | NO |
CVE-2018-10049MEDIUM iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel. | Apr 11, 2018 | 4.8 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
22.2% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Eswap
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.4 | 7 | 7.9 | 0.9% | 0 | 0 |
| 2.0 | 2 | 5.9 | 1.5% | 0 | 2 |