10
CVSSv2

CVE-2004-0348

Published: 23/11/2004 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote malicious users to execute arbitrary SQL via the userId parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

spidersales spidersales 2.0

Exploits

source: wwwsecurityfocuscom/bid/9799/info Multiple vulnerabilities have been identified in the application that may allow an attacker to obtain the private cryptographic key and gain access to sensitive information The application is also reported prone to an SQL injection vulnerability that may allow an attacker to gain administrative l ...