Shopex

Ecshop

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.25%
  • Veröffentlicht 31.08.2026 21:30:36
  • Zuletzt bearbeitet 01.09.2026 20:47:54

A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of the argument rec_id leads to sql injection. The attack can b...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 31.08.2026 21:15:35
  • Zuletzt bearbeitet 01.09.2026 20:47:54

A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the argument pack_img can lead to unrestricted upload. It is possible to launch the attack r...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 22.05.2024 16:15:10
  • Zuletzt bearbeitet 28.04.2025 17:01:44

Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php.

  • EPSS 0.59%
  • Veröffentlicht 04.04.2024 05:15:19
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SQL Injection vulnerability in ECshop 4.x allows an attacker to obtain sensitive information via the file/article.php component.

Exploit
  • EPSS 0.59%
  • Veröffentlicht 15.02.2024 13:15:46
  • Zuletzt bearbeitet 21.11.2024 08:50:45

A vulnerability, which was classified as critical, has been found in ECshop 4.1.8. Affected by this issue is some unknown functionality of the file /admin/view_sendlist.php. The manipulation leads to sql injection. The attack may be launched remotely...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 29.09.2023 22:15:12
  • Zuletzt bearbeitet 21.11.2024 08:41:28

A vulnerability has been found in ECshop 4.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/order.php. The manipulation of the argument goods_id leads to sql injection. The attack can be la...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 29.09.2023 21:15:10
  • Zuletzt bearbeitet 21.11.2024 08:41:28

A vulnerability, which was classified as critical, was found in ECshop 4.1.5. Affected is an unknown function of the file /admin/leancloud.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. ...

Exploit
  • EPSS 0.7%
  • Veröffentlicht 04.08.2023 17:15:11
  • Zuletzt bearbeitet 21.11.2024 08:14:45

ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel.

  • EPSS 0.75%
  • Veröffentlicht 06.03.2023 08:15:08
  • Zuletzt bearbeitet 21.11.2024 07:38:37

A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of the component New Product Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. T...

  • EPSS 0.75%
  • Veröffentlicht 06.03.2023 08:15:08
  • Zuletzt bearbeitet 21.11.2024 07:38:37

A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is some unknown functionality of the file admin/database.php of the component Backup Database Handler. The manipulation leads to unrest...