PT-2005-4547 · Alstrasoft · Alstrasoft Affiliate Network Pro

Robin Verton

·

Publicado

2005-11-24

·

Atualizado

2017-07-11

·

CVE-2005-3796

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AlstraSoft Affiliate Network Pro version 7.2
Description A direct static code injection issue exists in the admin options manage.php file, allowing attackers to execute arbitrary PHP code via the number parameter. It is unclear whether administrator privileges are required to exploit this issue.
Recommendations For AlstraSoft Affiliate Network Pro version 7.2, consider restricting access to the admin options manage.php file and the number parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3796

Produtos afetados

Alstrasoft Affiliate Network Pro