Vulnerabilities > Spidersales

DATE CVE VULNERABILITY TITLE RISK
2004-11-23 CVE-2004-0351 Multiple vulnerability in Spidersales 2.0
Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local users with access to the database to decrypt data.
local
low complexity
spidersales
2.1
2004-11-23 CVE-2004-0350 Multiple vulnerability in Spidersales 2.0
SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local users to obtain the private key by factoring.
local
low complexity
spidersales
2.1
2004-11-23 CVE-2004-0348 Multiple vulnerability in Spidersales 2.0
SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.
network
low complexity
spidersales
critical
10.0