VYPR
Vendor

Spidersales

Sign in to watch
Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2004-03480.030.01Nov 23, 2004SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.
CVE-2021-383500.000.00Sep 10, 2021The spideranalyse WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the date parameter found in the ~/analyse/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.1.
CVE-2004-03500.000.00Nov 23, 2004SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local users to obtain the private key by factoring.
CVE-2004-03510.000.00Nov 23, 2004Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local users with access to the database to decrypt data.