Vulnerabilities > CVE-2004-0348 - Multiple vulnerability in Spidersales 2.0

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
spidersales
critical
nessus
exploit available

Summary

SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.

Vulnerable Configurations

Part Description Count
Application
Spidersales
1

Exploit-Db

descriptionSpiderSales 2.0 Shopping Cart Multiple Vulnerabilities. CVE-2004-0348. Webapps exploit for asp platform
idEDB-ID:23791
last seen2016-02-02
modified2004-03-03
published2004-03-03
reporterNick Gudov
sourcehttps://www.exploit-db.com/download/23791/
titleSpiderSales 2.0 Shopping Cart Multiple Vulnerabilities

Nessus

NASL familyCGI abuses
NASL idSPIDERSALES_SQL_INJECTION.NASL
descriptionThe remote host is running the SpiderSales Shopping Cart CGI suite. There is a bug in this suite which may allow an attacker to force it to execute arbitrary SQL statements on the remote host. An attacker may use this flaw to gain the control of the remote website and possibly execute arbitrary commands on the remote host.
last seen2020-06-01
modified2020-06-02
plugin id12088
published2004-03-04
reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/12088
titleSpiderSales Shopping Cart SQL injection