Eswap

Vendor:

First CVE: Nov 2, 2011 · Active for 14 years

9
Total CVEs
More Total CVEs than 86% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Eswap over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 2, 2011
14 years ago
Most Recent CVE
May 25, 2018
2,983 days ago

CVE Severity & Scoring

Eswap9 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (77.8%)
Unknown2 (22.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (77.8%)
High0 (0.0%)
Unknown2 (22.2%)
User Interaction
None4 (44.4%)
Unknown2 (22.2%)
Required3 (33.3%)
Privileges Required
Low1 (11.1%)
High2 (22.2%)
None4 (44.4%)
Unknown2 (22.2%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.
Nov 2, 20117.532NOYES
iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.
May 22, 20189.830NONO
iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.
May 22, 20189.828NONO
iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.
May 25, 20188.827NONO
iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.
Apr 11, 20188.824NONO
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
Apr 11, 20187.222NONO
Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka the
Nov 2, 20114.322NOYES
iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.
Apr 16, 20186.117NONO
iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel.
Apr 11, 20184.816NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
22.2% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Eswap

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.477.90.9%00
2.025.91.5%02