PT-2005-4547 · Alstrasoft · Alstrasoft Affiliate Network Pro
Robin Verton
·
Publicado
2005-11-24
·
Atualizado
2017-07-11
·
CVE-2005-3796
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AlstraSoft Affiliate Network Pro version 7.2
Description
A direct static code injection issue exists in the admin options manage.php file, allowing attackers to execute arbitrary PHP code via the
number parameter. It is unclear whether administrator privileges are required to exploit this issue.Recommendations
For AlstraSoft Affiliate Network Pro version 7.2, consider restricting access to the admin options manage.php file and the
number parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alstrasoft Affiliate Network Pro