Shopex

Ecshop

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.11%
  • Veröffentlicht 22.05.2024 16:15:10
  • Zuletzt bearbeitet 28.04.2025 17:01:44

Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php.

  • EPSS 0.05%
  • Veröffentlicht 04.04.2024 05:15:19
  • Zuletzt bearbeitet 21.11.2024 09:12:44

SQL Injection vulnerability in ECshop 4.x allows an attacker to obtain sensitive information via the file/article.php component.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 15.02.2024 13:15:46
  • Zuletzt bearbeitet 21.11.2024 08:50:45

A vulnerability, which was classified as critical, has been found in ECshop 4.1.8. Affected by this issue is some unknown functionality of the file /admin/view_sendlist.php. The manipulation leads to sql injection. The attack may be launched remotely...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 29.09.2023 22:15:12
  • Zuletzt bearbeitet 21.11.2024 08:41:28

A vulnerability has been found in ECshop 4.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/order.php. The manipulation of the argument goods_id leads to sql injection. The attack can be la...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 29.09.2023 21:15:10
  • Zuletzt bearbeitet 21.11.2024 08:41:28

A vulnerability, which was classified as critical, was found in ECshop 4.1.5. Affected is an unknown function of the file /admin/leancloud.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. ...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 04.08.2023 17:15:11
  • Zuletzt bearbeitet 21.11.2024 08:14:45

ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel.

  • EPSS 0.08%
  • Veröffentlicht 06.03.2023 08:15:08
  • Zuletzt bearbeitet 21.11.2024 07:38:37

A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is some unknown functionality of the file admin/database.php of the component Backup Database Handler. The manipulation leads to unrest...

  • EPSS 0.08%
  • Veröffentlicht 06.03.2023 08:15:08
  • Zuletzt bearbeitet 21.11.2024 07:38:37

A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of the component New Product Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. T...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 11.02.2023 18:15:11
  • Zuletzt bearbeitet 21.11.2024 07:37:48

A vulnerability was found in EcShop 4.1.5. It has been classified as critical. This affects an unknown part of the file /ecshop/admin/template.php of the component PHP File Handler. The manipulation leads to unrestricted upload. It is possible to ini...

  • EPSS 28.34%
  • Veröffentlicht 28.06.2022 13:15:10
  • Zuletzt bearbeitet 21.11.2024 06:26:17

ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.