VYPR

Shaklee Product Catalog

by Shaklee Product Catalog Project

CVEs (4)

  • CVE-2008-6875Jul 24, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220.

  • CVE-2009-1321Apr 17, 2009
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

  • CVE-2014-7452Oct 19, 2014
    risk 0.00cvss epss 0.00

    The Shaklee Product Catalog (aka com.wProductCatalog) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2007-5220Oct 5, 2007
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in catalog.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter and possibly other parameters.