Extension WordPress
Vulnérabilités eShop
Cette page rassemble les failles publiées pour eShop, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de eShop
5 fiches
eShop <= 6.3.14 – Multiple Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.
*-6.3.14
Non indiqué
02/02/2016
eShop <= 6.3.14 – Multiple SQL Injections
Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2)…
*-6.3.14
Non indiqué
02/02/2016
eshop <= 6.3.13 – Cross-Site Forgery Request and Reflected Cross-Site Scripting
The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.
*-6.3.13
6.3.14
09/09/2015
eShop <= 6.3.11 – Cross-Site Scripting
The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via…
[*, 6.3.12)
6.3.12
06/05/2015
eShop < 6.2.9 – Reflected Cross-Site Scripting
The eshop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘eshoptemplate’ GET parameter in versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
[*, 6.2.9)
6.2.9
20/07/2011
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.