PT-2005-4544 · Alstrasoft · Alstrasoft Affiliate Network Pro

Robin Verton

·

Publicado

2005-11-24

·

Atualizado

2017-07-11

·

CVE-2005-3793

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AlstraSoft Affiliate Network Pro version 7.2
Description The issue allows remote attackers to bypass authentication and execute arbitrary SQL commands. This can be achieved via the username or password to admin/admin validate login, or the login, password, and flag parameters to "login validate.php".
Recommendations For AlstraSoft Affiliate Network Pro version 7.2, consider disabling the login functionality until a patch is available to prevent exploitation. Restrict access to the "login validate.php" endpoint to minimize the risk of SQL injection attacks. Avoid using the username, password, and flag parameters in the affected endpoint until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3793

Produtos afetados

Alstrasoft Affiliate Network Pro